NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 3542 | CVE-2008-3675 | Directory traversal vulnerability in classes/imgsize.php in Gelato 0.95 allows remote attackers to read arbitrary files via (1) a .. (dot dot) and possibly (2) a full pathname in the img parameter. NOTE: some of these details are obtained from third party information. | 2 | 5 | Medium | 2017-01-03 | 2009-02-06 | View | |
| 3543 | CVE-2008-3676 | Unspecified vulnerability in the IMAP server in hMailServer 4.4.1 allows remote authenticated users to cause a denial of service (resource exhaustion or daemon crash) via a long series of IMAP commands. | 2 | 4.3 | Medium | 2017-01-03 | 2009-02-06 | View | |
| 3544 | CVE-2008-3677 | Directory traversal vulnerability in includes/events_application_top.php in Freeway before 1.4.2.197 allows remote attackers to include and execute arbitrary local files via unspecified vectors. | 2 | 6.8 | Medium | 2017-01-03 | 2009-02-06 | View | |
| 3545 | CVE-2008-3678 | Cross-site scripting (XSS) vulnerability in admin/search_links.php in Freeway before 1.4.2.197 allows remote attackers to inject arbitrary web script or HTML via the URL. | 2 | 4.3 | Medium | 2017-01-03 | 2009-02-06 | View | |
| 3546 | CVE-2008-3679 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in IDevSpot PhpLinkExchange 1.01 allow remote attackers to inject arbitrary web script or HTML via the catid parameter in a (1) user_add, (2) recip, (3) tellafriend, or (4) contact action, or (5) in a request without an action; or (6) the id parameter in a tellafriend action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 4.3 | Medium | 2017-01-03 | 2009-02-06 | View |
Page 2740 of 17672, showing 5 records out of 88360 total, starting on record 13696, ending on 13700