NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 6397 | CVE-2008-6666 | Multiple cross-site scripting (XSS) vulnerabilities in Kronos webTA allow remote attackers to inject arbitrary web script or HTML via the description field to (1) servlet/com.threeis.webta.H710selProject and (2) servlet/com.threeis.webta.H720editProjectInfo. NOTE: BID:29610 states that the initial report was incorrect, but the reason for this conclusion is unknown. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-08 | View | |
| 2814 | CVE-2008-2920 | admin/filemanager/ (aka the File Manager) in EZTechhelp EZCMS 1.2 and earlier does not require authentication, which allows remote attackers to create, modify, read, and delete files. | 2 | 7.5 | High | 2017-01-03 | 2009-04-08 | View | |
| 2815 | CVE-2008-2921 | SQL injection vulnerability in index.php in EZTechhelp EZCMS 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-04-08 | View | |
| 6399 | CVE-2008-6668 | Multiple directory traversal vulnerabilities in nweb2fax 0.2.7 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) id parameter to comm.php and (2) var_filename parameter to viewrq.php. | 2 | 5 | Medium | 2017-01-03 | 2009-04-08 | View | |
| 48383 | CVE-2009-1073 | nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for the LDAP server by reading the bindpw field. | 2 | 4.9 | Medium | 2017-01-07 | 2009-04-08 | View |
Page 2962 of 17672, showing 5 records out of 88360 total, starting on record 14806, ending on 14810