NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 6084 | CVE-2008-6353 | SQL injection vulnerability in index.asp in ASP-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the cha parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-03-02 | View | |
| 6085 | CVE-2008-6354 | The Net Guys ASPired2poll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to ASPired2poll.mdb. | 2 | 5 | Medium | 2017-01-03 | 2009-03-02 | View | |
| 6086 | CVE-2008-6355 | The Net Guys ASPired2Protect stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to ASPired2Protect.mdb. | 2 | 5 | Medium | 2017-01-03 | 2009-03-02 | View | |
| 57365 | CVE-2007-5289 | HP Mercury Quality Center (QC) 9.2 and earlier, and possibly TestDirector, relies on cached client-side scripts to implement "workflow" and decisions about the "capability" of a user, which allows remote attackers to execute arbitrary code via crafted use of the Open Test Architecture (OTA) API, as demonstrated by modifying (1) common.tds, (2) defects.tds, (3) manrun.tds, (4) req.tds, (5) testlab.tds, or (6) testplan.tds in %tmp%TD_80, and then setting the file"s properties to read-only. | 2 | 7.6 | High | 2017-01-07 | 2009-03-03 | View | |
| 4912 | CVE-2008-5128 | Ocean12 Membership Manager Pro stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12member.mdb. | 2 | 5 | Medium | 2017-01-03 | 2009-03-03 | View |
Page 2809 of 17672, showing 5 records out of 88360 total, starting on record 14041, ending on 14045