NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 2007 | CVE-2008-2072 | Cross-site scripting (XSS) vulnerability in index.php in Virtual Design Studio vlbook 1.21 allows remote attackers to inject arbitrary web script or HTML via the l parameter, a different vector than CVE-2006-3260. | 2 | 4.3 | Medium | 2017-01-03 | 2009-01-29 | View | |
| 3287 | CVE-2008-3406 | SQL injection vulnerability in showcat.php in phpLinkat 0.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
| 4567 | CVE-2008-4753 | SQL injection vulnerability in EditUrl.php in AJ Square RSS Reader allows remote attackers to execute arbitrary SQL commands via the url parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
| 5335 | CVE-2008-5586 | SQL injection vulnerability in findoffice.php in Check Up New Generation (aka Check New) 4.52, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search parameter. | 2 | 6.8 | Medium | 2017-01-03 | 2009-01-29 | View | |
| 5591 | CVE-2008-5860 | Directory traversal vulnerability in backend/template.php in Constructr CMS 3.02.5 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to create or read arbitrary files via directory traversal sequences in the edit_file parameter. | 2 | 5.1 | Medium | 2017-01-03 | 2009-01-29 | View |
Page 2688 of 17672, showing 5 records out of 88360 total, starting on record 13436, ending on 13440