NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
1926 | CVE-2008-1990 | Multiple SQL injection vulnerabilities in Acidcat CMS 3.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) cID parameter to default.asp and the (2) username parameter to main_login2.asp. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
1927 | CVE-2008-1991 | Cross-site scripting (XSS) vulnerability in admin_colors_swatch.asp in Acidcat CMS 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the field parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2009-01-29 | View | |
1928 | CVE-2008-1992 | Acidcat CMS 3.4.1 does not properly restrict access to (1) default_mail_aspemail.asp, (2) default_mail_cdosys.asp or (3) default_mail_jmail.asp, which allows remote attackers to bypass restrictions and relay email messages with modified From, FromName, and To fields. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
1929 | CVE-2008-1993 | Acidcat CMS 3.4.1 does not restrict access to the FCKEditor component, which allows remote attackers to upload arbitrary files. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
1930 | CVE-2008-1994 | Multiple stack-based buffer overflows in (a) acon.c, (b) menu.c, and (c) child.c in Acon 1.0.5-5 through 1.0.5-7 allow local users to execute arbitrary code via (1) a long HOME environment variable or (2) a large number of terminal columns. | 2 | 7.2 | High | 2017-01-03 | 2008-09-05 | View |
Page 386 of 17672, showing 5 records out of 88360 total, starting on record 1926, ending on 1930