NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 70288 | CVE-2005-4699 | Argument injection vulnerability in TellMe 1.2 and earlier allows remote attackers to modify command line arguments for the Whois program and obtain sensitive information via "--" style options in the q_Host parameter. | 2 | 6.4 | Medium | 2017-01-03 | 2008-09-05 | View | |
| 5008 | CVE-2008-5224 | Cross-site scripting (XSS) vulnerability in Kent Web Mart 1.61 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-01 | View | |
| 5264 | CVE-2008-5515 | Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access restrictions and conduct directory traversal attacks via .. (dot dot) sequences and the WEB-INF directory in a Request. | 2 | 5 | Medium | 2017-01-03 | 2016-08-22 | View | |
| 5520 | CVE-2008-5780 | Forest Blog 1.3.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing passwords via a direct request for blog.mdb. | 2 | 5 | Medium | 2017-01-03 | 2009-01-29 | View | |
| 5776 | CVE-2008-6045 | Session fixation vulnerability in shopping_cart.php in xt:Commerce 3.0.4 and earlier allows remote attackers to hijack web sessions by setting the XTCsid parameter. | 2 | 6.8 | Medium | 2017-01-03 | 2009-08-19 | View |
Page 2829 of 17672, showing 5 records out of 88360 total, starting on record 14141, ending on 14145