NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 4336 | CVE-2008-4513 | Cross-site scripting (XSS) vulnerability in BBcode API module in Phorum 5.2.8 allows remote attackers to inject arbitrary web script or HTML via nested BBcode image tags. | 2 | 4.3 | Medium | 2017-01-03 | 2009-02-21 | View | |
| 5948 | CVE-2008-6217 | Cross-site scripting (XSS) vulnerability in index.php in Extrakt Framework 0.7 allows remote attackers to inject arbitrary web script or HTML via the plugins[file][id] parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 4.3 | Medium | 2017-01-03 | 2009-02-22 | View | |
| 5953 | CVE-2008-6222 | Directory traversal vulnerability in the Pro Desk Support Center (com_pro_desk) component 1.0 and 1.2 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the include_file parameter to index.php. | 2 | 5 | Medium | 2017-01-03 | 2009-02-23 | View | |
| 47979 | CVE-2009-0650 | Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 and earlier, and possibly 5.02, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a STATS line with a long pwd field. NOTE: some of these details are obtained from third party information. | 2 | 10 | High | 2017-01-07 | 2009-02-23 | View | |
| 48003 | CVE-2009-0677 | avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remote authenticated users to execute arbitrary code via PHP sequences in an element of the replacements array, which is processed by the preg_replace function with the eval switch, as specified in an element of the patterns array. | 2 | 6.5 | Medium | 2017-01-07 | 2009-02-23 | View |
Page 2779 of 17672, showing 5 records out of 88360 total, starting on record 13891, ending on 13895