NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 6255 | CVE-2008-6524 | resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrary users via a modified uid parameter. NOTE: this can be leveraged with a separate vulnerability in auth.php to modify passwords without authentication. | 2 | 6.5 | Medium | 2017-01-03 | 2009-04-08 | View | |
| 6511 | CVE-2008-6780 | SQL injection vulnerability in directory.php in Scripts for Sites (SFS) SFS EZ Affiliate allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action. | 2 | 7.5 | High | 2017-01-03 | 2009-05-01 | View | |
| 6767 | CVE-2008-7036 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier, and DevTracker module 0.20 for E-XooPS 1.0.8 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) direction and (2) order_by parameters. | 2 | 4.3 | Medium | 2017-01-03 | 2009-08-24 | View | |
| 7023 | CVE-2008-7297 | Opera cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue. | 2 | 5.8 | Medium | 2017-01-03 | 2012-08-02 | View | |
| 73583 | CVE-2003-0455 | The imagemagick libmagick library 5.5 and earlier creates temporary files insecurely, which allows local users to create or overwrite arbitrary files. | 2 | 4.6 | Medium | 2017-01-03 | 2016-10-17 | View |
Page 2531 of 17672, showing 5 records out of 88360 total, starting on record 12651, ending on 12655