NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
70288  CVE-2005-4699  Argument injection vulnerability in TellMe 1.2 and earlier allows remote attackers to modify command line arguments for the Whois program and obtain sensitive information via "--" style options in the q_Host parameter.    6.4  Medium  2017-01-03  2008-09-05  View
5008  CVE-2008-5224  Cross-site scripting (XSS) vulnerability in Kent Web Mart 1.61 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.    4.3  Medium  2017-01-03  2009-04-01  View
5264  CVE-2008-5515  Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access restrictions and conduct directory traversal attacks via .. (dot dot) sequences and the WEB-INF directory in a Request.    Medium  2017-01-03  2016-08-22  View
5520  CVE-2008-5780  Forest Blog 1.3.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing passwords via a direct request for blog.mdb.    Medium  2017-01-03  2009-01-29  View
5776  CVE-2008-6045  Session fixation vulnerability in shopping_cart.php in xt:Commerce 3.0.4 and earlier allows remote attackers to hijack web sessions by setting the XTCsid parameter.    6.8  Medium  2017-01-03  2009-08-19  View

Page 2829 of 17672, showing 5 records out of 88360 total, starting on record 14141, ending on 14145

Actions