NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 3892 | CVE-2008-4032 | Microsoft Office SharePoint Server 2007 Gold and SP1 and Microsoft Search Server 2008 do not properly perform authentication and authorization for administrative functions, which allows remote attackers to cause a denial of service (server load), obtain sensitive information, and "create scripts that would run in the context of the site" via requests to administrative URIs, aka "Access Control Vulnerability." | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
| 69940 | CVE-2005-4342 | ColdFusion Sandbox on Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 does not throw an exception if the SecurityManager is disabled, which might allow remote attackers to "bypass security controls," aka "JRun Clustered Sandbox Security Vulnerability." | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
| 4916 | CVE-2008-5132 | SQL injection vulnerability in inc/ajax/ajax_rating.php in MemHT Portal 4.0.1 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header. | 2 | 7.5 | High | 2017-01-03 | 2012-10-30 | View | |
| 5684 | CVE-2008-5953 | Directory traversal vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter to the default URI. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
| 5940 | CVE-2008-6209 | SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-02-20 | View |
Page 2522 of 17672, showing 5 records out of 88360 total, starting on record 12606, ending on 12610