NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
2636  CVE-2008-2742  Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/config.php) in Achievo 1.2.0 through 1.3.2 allows remote attackers to execute arbitrary code by uploading a file with .php followed by a safe extension, then accessing it via a direct request to the file in the Achievo root directory. NOTE: this is only a vulnerability in environments that support multiple extensions, such as Apache with the mod_mime module enabled.    7.5  High  2017-01-03  2009-04-14  View
69196  CVE-2005-3535  Buffer overflow in KETM 0.0.6 allows local users to execute arbitrary code via unknown vectors.    7.5  High  2017-01-03  2008-09-05  View
3916  CVE-2008-4058  The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to (1) chrome XBL and (2) chrome JS.    7.5  High  2017-01-03  2013-07-27  View
4172  CVE-2008-4344  SQL injection vulnerability in cat.php in 6rbScript allows remote attackers to execute arbitrary SQL commands via the CatID parameter.    7.5  High  2017-01-03  2009-08-19  View
4428  CVE-2008-4614  PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to create and delete forums, topics, and replies.    7.5  High  2017-01-03  2009-01-29  View

Page 2791 of 17672, showing 5 records out of 88360 total, starting on record 13951, ending on 13955

Actions