NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
48496  CVE-2009-1208  SQL injection vulnerability in auth2db 0.2.5, and possibly other versions before 0.2.7, uses the addslashes function instead of the mysql_real_escape_string function, which allows remote attackers to conduct SQL injection attacks using multibyte character encodings.    7.5  High  2017-01-07  2009-04-02  View
2418  CVE-2008-2510  SQL injection vulnerability in wp-uploadfile.php in the Upload File plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the f_id parameter.    7.5  High  2017-01-03  2009-04-02  View
2678  CVE-2008-2784  The smtp_filter function in spamdyke before 3.1.8 does not filter RCPT commands after encountering the first DATA command, which allows remote attackers to use the server as an open mail relay by sending RCPT commands with invalid recipients, followed by a DATA command, followed by arbitrary RCPT commands and a second DATA command.    6.4  Medium  2017-01-03  2009-04-02  View
1657  CVE-2008-1716  Cross-site scripting (XSS) vulnerability in WoltLab Community Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5 allows remote attackers to inject arbitrary web script or HTML via the (1) page and (2) form parameters, which are not properly handled when they are reflected back in an error message.    4.3  Medium  2017-01-03  2009-04-02  View
1658  CVE-2008-1717  WoltLab Community Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5 allows remote attackers to obtain the full path via invalid (1) page and (2) form parameters, which leaks the path from an exception handler when a valid class cannot be found.    Medium  2017-01-03  2009-04-02  View

Page 2926 of 17672, showing 5 records out of 88360 total, starting on record 14626, ending on 14630

Actions