NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 6087 | CVE-2008-6356 | evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to (1) evcal.mdb and (2) evcal97.mdb. | 2 | 5 | Medium | 2017-01-03 | 2011-03-07 | View | |
| 6343 | CVE-2008-6612 | Unrestricted file upload vulnerability in admin/uploader.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in img/. | 2 | 6.8 | Medium | 2017-01-03 | 2009-04-06 | View | |
| 6599 | CVE-2008-6868 | Cross-site scripting (XSS) vulnerability in default/login.php in EditeurScripts EsBaseAdmin 2.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the EsContacts 1.0 issue is covered in CVE-2008-2037. | 2 | 4.3 | Medium | 2017-01-03 | 2009-08-19 | View | |
| 6855 | CVE-2008-7124 | zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allows remote attackers to gain administrator privileges via a direct request, as demonstrated by adding a new administrator. | 2 | 7.5 | High | 2017-01-03 | 2009-08-31 | View | |
| 73159 | CVE-2003-0011 | Unknown vulnerability in the DNS intrusion detection application filter for Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (blocked traffic to DNS servers) via a certain type of incoming DNS request that is not properly handled. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 3314 of 17672, showing 5 records out of 88360 total, starting on record 16566, ending on 16570