NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 5516 | CVE-2008-5776 | Multiple directory traversal vulnerabilities in Aperto Blog 0.1.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) action parameter to admin.php and the (2) get parameter to index.php. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL. | 2 | 7.5 | High | 2017-01-03 | 2008-12-31 | View | |
| 5772 | CVE-2008-6041 | Multiple cross-site scripting (XSS) vulnerabilities in Index.asp in Dataspade 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) ViewName, (2) TableName, (3) OrderBy, and (4) FilterField parameters. | 2 | 4.3 | Medium | 2017-01-03 | 2009-02-03 | View | |
| 6028 | CVE-2008-6297 | Cross-site scripting (XSS) vulnerability in order.php in DHCart allows remote attackers to inject arbitrary web script or HTML via the (1) domain and (2) d1 parameters. | 2 | 4.3 | Medium | 2017-01-03 | 2009-03-13 | View | |
| 6284 | CVE-2008-6553 | microcms-admin-home.php in Implied by Design Micro CMS (Micro-CMS) 3.5 (aka 0.3.5) does not require authentication as an administrator, which allows remote attackers to (1) create administrative accounts via an add_admin action, (2) remove administrative accounts via a delete_admin action, and (3) modify administrative passwords via a change_password action. | 2 | 7.5 | High | 2017-01-03 | 2009-08-11 | View | |
| 6540 | CVE-2008-6809 | SQL injection vulnerability in hotel_habitaciones.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 allows remote attackers to execute arbitrary SQL commands via the HotelID parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-05-18 | View |
Page 2794 of 17672, showing 5 records out of 88360 total, starting on record 13966, ending on 13970