NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
4465  CVE-2008-4651  Multiple SQL injection vulnerabilities in Jetbox CMS 2.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby parameter to admin/cms/images.php and the (2) nav_id parameter in an editrecord action to admin/cms/nav.php.    Medium  2017-01-03  2008-10-22  View
70001  CVE-2005-4403  SQL injection vulnerability in index.php in Marwel 2.7 and earlier allows remote attackers to execute arbitrary SQL commands via the show parameter.    7.5  High  2017-01-03  2008-09-20  View
4721  CVE-2008-4932  webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files via an absolute pathname in the path parameter and arbitrary content in the content parameter. NOTE: this can be leveraged for code execution by writing to a file under the web document root.    High  2017-01-03  2009-02-26  View
70257  CVE-2005-4668  The embedded HSQLDB in ParosProxy before 3.2.7, when running with JDK 1.4.2 before 1.4.2_08, allows local users to execute arbitrary comands via crafted SQL commands that interact with HSQLDB through JDBC, a similar vulnerability to CVE-2003-0845.    4.6  Medium  2017-01-03  2008-09-05  View
4977  CVE-2008-5193  Cross-site scripting (XSS) vulnerability in search.asp in W1L3D4 Philboard 1.14 and 1.2 allows remote attackers to inject arbitrary web script or HTML via the searchterms parameter. NOTE: this might overlap CVE-2007-4024.    4.3  Medium  2017-01-03  2009-08-20  View

Page 2547 of 17672, showing 5 records out of 88360 total, starting on record 12731, ending on 12735

Actions