NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 5315 | CVE-2008-5566 | Cross-site scripting (XSS) vulnerability in index.php in Triangle Solutions PHP Multiple Newsletters 2.7 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | 2 | 4.3 | Medium | 2017-01-03 | 2009-03-18 | View | |
| 5319 | CVE-2008-5570 | Directory traversal vulnerability in index.php in PHP Multiple Newsletters 2.7, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter. | 2 | 6.8 | Medium | 2017-01-03 | 2009-03-18 | View | |
| 5320 | CVE-2008-5571 | SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter (aka user field) or the (2) psw parameter (aka passwd field). NOTE: some of these details are obtained from third party information. | 2 | 7.5 | High | 2017-01-03 | 2009-03-18 | View | |
| 6088 | CVE-2008-6357 | MyCal Personal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to mycal.mdb. | 2 | 5 | Medium | 2017-01-03 | 2009-03-18 | View | |
| 5322 | CVE-2008-5573 | SQL injection vulnerability in the login feature in Poll Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) Password and (2) username parameters. | 2 | 7.5 | High | 2017-01-03 | 2009-03-18 | View |
Page 2874 of 17672, showing 5 records out of 88360 total, starting on record 14366, ending on 14370