NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
5328  CVE-2008-5579  Absolute path traversal vulnerability in mini-pub.php/front-end/cat.php in mini-pub 0.3 allows remote attackers to read arbitrary files via a full pathname in the sFileName parameter.    Medium  2017-01-03  2009-01-29  View
5584  CVE-2008-5853  Chilek Content Management System (aka ChiCoMaS) 2.0.4 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to (1) obtain database credentials via a direct request for config.inc or (2) read database backups via a request for a backup/ URI.    Medium  2017-01-03  2009-01-29  View
5329  CVE-2008-5580  mini-pub.php/front-end/cat.php in mini-pub 0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the sFileName argument.    7.5  High  2017-01-03  2009-01-29  View
5585  CVE-2008-5854  Multiple cross-site scripting (XSS) vulnerabilities in login.php in myPHPscripts Login Session 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) ls_user and (2) ls_email parameters (aka the User form) in an ls_register action. NOTE: some of these details are obtained from third party information.    4.3  Medium  2017-01-03  2009-01-29  View
2258  CVE-2008-2339  SQL injection vulnerability in index.php in Turnkey Web Tools SunShop Shopping Cart 3.5.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in an item action, a different vector than CVE-2008-2038, CVE-2007-4597, and CVE-2007-2549.    7.5  High  2017-01-03  2009-01-29  View

Page 2684 of 17672, showing 5 records out of 88360 total, starting on record 13416, ending on 13420

Actions