NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
2576  CVE-2008-2678  Multiple SQL injection vulnerabilities in Telephone Directory 2008, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) code parameter in a confirm_data action to edit1.php and the (2) id parameter to view_more.php.    7.5  High  2017-01-03  2009-04-14  View
2577  CVE-2008-2679  SQL injection vulnerability in the KeyWordsList function in _includes/inc_routines.asp in Realm CMS 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the kwrd parameter in a kwl action to the default URI.    7.5  High  2017-01-03  2008-09-10  View
2578  CVE-2008-2680  Multiple cross-site scripting (XSS) vulnerabilities in _db/compact.asp in Realm CMS 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) CmpctedDB and (2) Boyut parameters.    4.3  Medium  2017-01-03  2008-09-10  View
2579  CVE-2008-2681  Realm CMS 2.3 and earlier allows remote attackers to obtain sensitive information via a direct request to _db/compact.asp, which reveals the database path in an error message.    Medium  2017-01-03  2008-09-10  View
2580  CVE-2008-2682  _RealmAdmin/login.asp in Realm CMS 2.3 and earlier allows remote attackers to bypass authentication and access admin pages via certain modified cookies, probably including (1) cUserRole, (2) cUserName, and (3) cUserID.    7.5  High  2017-01-03  2008-09-10  View

Page 516 of 17672, showing 5 records out of 88360 total, starting on record 2576, ending on 2580

Actions