NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
5662  CVE-2008-5931  The Net Guys ASPired2Blog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for admin/blog.mdb. NOTE: some of these details are obtained from third party information.    Medium  2017-01-03  2009-01-29  View
1055  CVE-2008-1094  SQL injection vulnerability in index.cgi in the Account View page in Barracuda Spam Firewall (BSF) before 3.5.12.007 allows remote authenticated administrators to execute arbitrary SQL commands via a pattern_x parameter in a search_count_equals action, as demonstrated by the pattern_0 parameter.    6.5  Medium  2017-01-03  2009-01-29  View
4127  CVE-2008-4299  A certain ActiveX control in the Microsoft Internet Authentication Service (IAS) Helper COM Component in iashlpr.dll allows remote attackers to cause a denial of service (browser crash) via a large integer value in the first argument to the PutProperty method. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.    Medium  2017-01-03  2009-01-29  View
5407  CVE-2008-5665  SQL injection vulnerability in index.php in the xhresim module in XOOPS allows remote attackers to execute arbitrary SQL commands via the no parameter.    7.5  High  2017-01-03  2009-01-29  View
5663  CVE-2008-5932  CodeAvalanche FreeForum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for _private/CAForum.mdb. NOTE: some of these details are obtained from third party information.    Medium  2017-01-03  2009-01-29  View

Page 2602 of 17672, showing 5 records out of 88360 total, starting on record 13006, ending on 13010

Actions