NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 2636 | CVE-2008-2742 | Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/config.php) in Achievo 1.2.0 through 1.3.2 allows remote attackers to execute arbitrary code by uploading a file with .php followed by a safe extension, then accessing it via a direct request to the file in the Achievo root directory. NOTE: this is only a vulnerability in environments that support multiple extensions, such as Apache with the mod_mime module enabled. | 2 | 7.5 | High | 2017-01-03 | 2009-04-14 | View | |
| 69196 | CVE-2005-3535 | Buffer overflow in KETM 0.0.6 allows local users to execute arbitrary code via unknown vectors. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
| 3916 | CVE-2008-4058 | The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to (1) chrome XBL and (2) chrome JS. | 2 | 7.5 | High | 2017-01-03 | 2013-07-27 | View | |
| 4172 | CVE-2008-4344 | SQL injection vulnerability in cat.php in 6rbScript allows remote attackers to execute arbitrary SQL commands via the CatID parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-08-19 | View | |
| 4428 | CVE-2008-4614 | PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to create and delete forums, topics, and replies. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View |
Page 2791 of 17672, showing 5 records out of 88360 total, starting on record 13951, ending on 13955