NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
6397  CVE-2008-6666  Multiple cross-site scripting (XSS) vulnerabilities in Kronos webTA allow remote attackers to inject arbitrary web script or HTML via the description field to (1) servlet/com.threeis.webta.H710selProject and (2) servlet/com.threeis.webta.H720editProjectInfo. NOTE: BID:29610 states that the initial report was incorrect, but the reason for this conclusion is unknown.    4.3  Medium  2017-01-03  2009-04-08  View
2814  CVE-2008-2920  admin/filemanager/ (aka the File Manager) in EZTechhelp EZCMS 1.2 and earlier does not require authentication, which allows remote attackers to create, modify, read, and delete files.    7.5  High  2017-01-03  2009-04-08  View
2815  CVE-2008-2921  SQL injection vulnerability in index.php in EZTechhelp EZCMS 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.    7.5  High  2017-01-03  2009-04-08  View
6399  CVE-2008-6668  Multiple directory traversal vulnerabilities in nweb2fax 0.2.7 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) id parameter to comm.php and (2) var_filename parameter to viewrq.php.    Medium  2017-01-03  2009-04-08  View
48383  CVE-2009-1073  nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for the LDAP server by reading the bindpw field.    4.9  Medium  2017-01-07  2009-04-08  View

Page 2962 of 17672, showing 5 records out of 88360 total, starting on record 14806, ending on 14810

Actions