NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
2007  CVE-2008-2072  Cross-site scripting (XSS) vulnerability in index.php in Virtual Design Studio vlbook 1.21 allows remote attackers to inject arbitrary web script or HTML via the l parameter, a different vector than CVE-2006-3260.    4.3  Medium  2017-01-03  2009-01-29  View
3287  CVE-2008-3406  SQL injection vulnerability in showcat.php in phpLinkat 0.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.    7.5  High  2017-01-03  2009-01-29  View
4567  CVE-2008-4753  SQL injection vulnerability in EditUrl.php in AJ Square RSS Reader allows remote attackers to execute arbitrary SQL commands via the url parameter.    7.5  High  2017-01-03  2009-01-29  View
5335  CVE-2008-5586  SQL injection vulnerability in findoffice.php in Check Up New Generation (aka Check New) 4.52, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search parameter.    6.8  Medium  2017-01-03  2009-01-29  View
5591  CVE-2008-5860  Directory traversal vulnerability in backend/template.php in Constructr CMS 3.02.5 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to create or read arbitrary files via directory traversal sequences in the edit_file parameter.    5.1  Medium  2017-01-03  2009-01-29  View

Page 2688 of 17672, showing 5 records out of 88360 total, starting on record 13436, ending on 13440

Actions