NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
56114  CVE-2007-3978  Session fixation vulnerability in bwired allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.    4.3  Medium  2017-01-07  2009-07-28  View
6608  CVE-2008-6877  ** DISPUTED ** Directory traversal vulnerability in admin/includes/initsystem.php in Zen Cart 1.3.8 and 1.3.8a, when .htaccess is not supported, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the loader_file parameter. NOTE: the vendor disputes this issue, stating "at worst, the use of this vulnerability will reveal some local file paths."    6.8  Medium  2017-01-03  2009-07-28  View
6609  CVE-2008-6878  ** DISPUTED ** Directory traversal vulnerability in admin/includes/languages/english.php in Zen Cart 1.3.8a, 1.3.8, and earlier, when .htaccess is not supported, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the _SESSION[language] parameter. NOTE: the vendor disputes this issue, stating "at worst, the use of this vulnerability will reveal some local file paths."    6.8  Medium  2017-01-03  2009-07-28  View
2918  CVE-2008-3028  Multiple cross-site scripting (XSS) vulnerabilities in the Send-A-Card (sr_sendcard) extension 2.2.2 and earlier for TYPO3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.    4.3  Medium  2017-01-03  2009-07-29  View
1641  CVE-2008-1700  The Web TransferCtrl Class 8,2,1,4 (iManFile.cab), as used in WorkSite Web 8.2 before SP1 P2, allows remote attackers to cause a denial of service (memory consumption) via a large number of SendNrlLink directives, which opens a separate window for each directive.    9.3  High  2017-01-03  2009-07-29  View

Page 3257 of 17672, showing 5 records out of 88360 total, starting on record 16281, ending on 16285

Actions