NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 2975 | CVE-2008-3090 | Multiple SQL injection vulnerabilities in index.php in BlognPlus (BURO GUN +) 2.5.5 MySQL and PostgreSQL editions allow remote attackers to execute arbitrary SQL commands via the (1) p, (2) e, (3) d, and (4) m parameters, a different vulnerability than CVE-2008-2819. | 2 | 7.5 | High | 2017-01-03 | 2009-05-14 | View | |
| 2978 | CVE-2008-3093 | Unrestricted file upload vulnerability in ImperialBB 2.3.5 and earlier allows remote authenticated users to upload and execute arbitrary PHP code by placing a .php filename in the Upload_Avatar parameter and sending the image/gif content type. | 2 | 6.5 | Medium | 2017-01-03 | 2009-05-14 | View | |
| 2979 | CVE-2008-3094 | The Organic Groups (OG) module 5.x before 5.x-7.3 and 6.x before 6.x-1.0-RC1, a module for Drupal, allows remote attackers to obtain sensitive information (private group names) via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-03 | 2009-05-14 | View | |
| 5548 | CVE-2008-5808 | Cross-site scripting (XSS) vulnerability in Six Apart Movable Type Enterprise (MTE) 1.x before 1.56; Movable Type (MT) 3.x before 3.38; and Movable Type, Movable Type Open Source (MTOS), and Movable Type Enterprise 4.x before 4.23 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to "application management." | 2 | 4.3 | Medium | 2017-01-03 | 2009-05-14 | View | |
| 3003 | CVE-2008-3119 | SQL injection vulnerability in index.php in DreamPics Builder allows remote attackers to execute arbitrary SQL commands via the page parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-05-14 | View |
Page 3062 of 17672, showing 5 records out of 88360 total, starting on record 15306, ending on 15310