NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
6084  CVE-2008-6353  SQL injection vulnerability in index.asp in ASP-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the cha parameter.    7.5  High  2017-01-03  2009-03-02  View
6085  CVE-2008-6354  The Net Guys ASPired2poll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to ASPired2poll.mdb.    Medium  2017-01-03  2009-03-02  View
6086  CVE-2008-6355  The Net Guys ASPired2Protect stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to ASPired2Protect.mdb.    Medium  2017-01-03  2009-03-02  View
57365  CVE-2007-5289  HP Mercury Quality Center (QC) 9.2 and earlier, and possibly TestDirector, relies on cached client-side scripts to implement "workflow" and decisions about the "capability" of a user, which allows remote attackers to execute arbitrary code via crafted use of the Open Test Architecture (OTA) API, as demonstrated by modifying (1) common.tds, (2) defects.tds, (3) manrun.tds, (4) req.tds, (5) testlab.tds, or (6) testplan.tds in %tmp%TD_80, and then setting the file"s properties to read-only.    7.6  High  2017-01-07  2009-03-03  View
4912  CVE-2008-5128  Ocean12 Membership Manager Pro stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12member.mdb.    Medium  2017-01-03  2009-03-03  View

Page 2809 of 17672, showing 5 records out of 88360 total, starting on record 14041, ending on 14045

Actions