NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
3786  CVE-2008-3924  The "Make a backup" functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover (1) account names and (2) password hashes via a direct request for (a) backup/cmme_data.zip or (b) backup/cmme_cmme.zip. NOTE: it was later reported that vector a also affects CMME 1.19.    4.3  Medium  2017-01-03  2009-02-17  View
47819  CVE-2009-0487  Cross-site scripting (XSS) vulnerability in Mahara before 1.0.9 allows remote attackers to inject arbitrary web script or HTML via a crafted forum post.    4.3  Medium  2017-01-07  2009-02-17  View
47820  CVE-2009-0488  Cross-site scripting (XSS) vulnerability in Phorum before 5.2.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.    4.3  Medium  2017-01-07  2009-02-17  View
4315  CVE-2008-4492  SQL injection vulnerability in referrals.php in YourOwnBux 4.0 allows remote attackers to execute arbitrary SQL commands via the usNick cookie.    7.5  High  2017-01-03  2009-02-17  View
4317  CVE-2008-4494  SQL injection vulnerability in completed-advance.php in TorrentTrader Classic 1.08 and 1.04 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.    7.5  High  2017-01-03  2009-02-17  View

Page 2766 of 17672, showing 5 records out of 88360 total, starting on record 13826, ending on 13830

Actions