NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
6105  CVE-2008-6374  CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to db/MailingList.mdb.    Medium  2017-01-03  2009-03-03  View
5082  CVE-2008-5304  Cross-site scripting (XSS) vulnerability in TWiki before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via the %URLPARAM{}% variable.    4.3  Medium  2017-01-03  2009-03-03  View
5083  CVE-2008-5305  Eval injection vulnerability in TWiki before 4.2.4 allows remote attackers to execute arbitrary Perl code via the %SEARCH{}% variable.    10  High  2017-01-03  2009-03-03  View
6107  CVE-2008-6376  SQL injection vulnerability in main.asp in Jbook allows remote attackers to execute arbitrary SQL commands via the password (pass parameter).    7.5  High  2017-01-03  2009-03-03  View
6109  CVE-2008-6378  SQL injection vulnerability in calendar_Eventupdate.asp in Calendar Mx Professional 2.0.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.    7.5  High  2017-01-03  2009-03-03  View

Page 2814 of 17672, showing 5 records out of 88360 total, starting on record 14066, ending on 14070

Actions