NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 48496 | CVE-2009-1208 | SQL injection vulnerability in auth2db 0.2.5, and possibly other versions before 0.2.7, uses the addslashes function instead of the mysql_real_escape_string function, which allows remote attackers to conduct SQL injection attacks using multibyte character encodings. | 2 | 7.5 | High | 2017-01-07 | 2009-04-02 | View | |
| 2418 | CVE-2008-2510 | SQL injection vulnerability in wp-uploadfile.php in the Upload File plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the f_id parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-04-02 | View | |
| 2678 | CVE-2008-2784 | The smtp_filter function in spamdyke before 3.1.8 does not filter RCPT commands after encountering the first DATA command, which allows remote attackers to use the server as an open mail relay by sending RCPT commands with invalid recipients, followed by a DATA command, followed by arbitrary RCPT commands and a second DATA command. | 2 | 6.4 | Medium | 2017-01-03 | 2009-04-02 | View | |
| 1657 | CVE-2008-1716 | Cross-site scripting (XSS) vulnerability in WoltLab Community Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5 allows remote attackers to inject arbitrary web script or HTML via the (1) page and (2) form parameters, which are not properly handled when they are reflected back in an error message. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-02 | View | |
| 1658 | CVE-2008-1717 | WoltLab Community Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5 allows remote attackers to obtain the full path via invalid (1) page and (2) form parameters, which leaks the path from an exception handler when a valid class cannot be found. | 2 | 5 | Medium | 2017-01-03 | 2009-04-02 | View |
Page 2926 of 17672, showing 5 records out of 88360 total, starting on record 14626, ending on 14630