NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 5513 | CVE-2008-5773 | Nukedit 4.9.8 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for database/dbsite.mdb. | 2 | 5 | Medium | 2017-01-03 | 2009-01-29 | View | |
| 3978 | CVE-2008-4120 | Multiple cross-site scripting (XSS) vulnerabilities in FlatPress 0.804 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) pass parameter to login.php, or the (3) name parameter to contact.php. | 2 | 4.3 | Medium | 2017-01-03 | 2009-01-29 | View | |
| 5003 | CVE-2008-5219 | The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified npass and npass1 parameters. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
| 5515 | CVE-2008-5775 | SQL injection vulnerability in categories.php in Aperto Blog 0.1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
| 3980 | CVE-2008-4122 | Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. | 2 | 5 | Medium | 2017-01-03 | 2009-01-29 | View |
Page 2651 of 17672, showing 5 records out of 88360 total, starting on record 13251, ending on 13255