NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
6255  CVE-2008-6524  resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrary users via a modified uid parameter. NOTE: this can be leveraged with a separate vulnerability in auth.php to modify passwords without authentication.    6.5  Medium  2017-01-03  2009-04-08  View
6511  CVE-2008-6780  SQL injection vulnerability in directory.php in Scripts for Sites (SFS) SFS EZ Affiliate allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.    7.5  High  2017-01-03  2009-05-01  View
6767  CVE-2008-7036  Multiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier, and DevTracker module 0.20 for E-XooPS 1.0.8 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) direction and (2) order_by parameters.    4.3  Medium  2017-01-03  2009-08-24  View
7023  CVE-2008-7297  Opera cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.    5.8  Medium  2017-01-03  2012-08-02  View
73583  CVE-2003-0455  The imagemagick libmagick library 5.5 and earlier creates temporary files insecurely, which allows local users to create or overwrite arbitrary files.    4.6  Medium  2017-01-03  2016-10-17  View

Page 2531 of 17672, showing 5 records out of 88360 total, starting on record 12651, ending on 12655

Actions