NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
5627  CVE-2008-5896  CodeAvalanche RateMySite stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CARateMySite.mdb. NOTE: some of these details are obtained from third party information.    7.5  High  2017-01-03  2009-01-29  View
2044  CVE-2008-2110  Unrestricted file upload vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request.    7.5  High  2017-01-03  2009-01-29  View
3580  CVE-2008-3715  Cross-site scripting (XSS) vulnerability in inc-core-admin-editor-previouscolorsjs.php in the FlexCMS 2.5 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the PreviousColorsString parameter.    2.6  Low  2017-01-03  2009-01-29  View
4860  CVE-2008-5073  Heap-based buffer overflow in an ActiveX control in Novell ZENworks Desktop Management 6.5 allows remote attackers to execute arbitrary code via a long argument to the CanUninstall method.    9.3  High  2017-01-03  2009-01-29  View
4349  CVE-2008-4526  Multiple directory traversal vulnerabilities in CCMS 3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skin parameter to (1) index.php, (2) forums.php, (3) admin.php, (4) header.php, (5) pages/story.php and (6) pages/poll.php.    10  High  2017-01-03  2009-01-29  View

Page 2710 of 17672, showing 5 records out of 88360 total, starting on record 13546, ending on 13550

Actions