NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
2596  CVE-2008-2698  Multiple cross-site scripting (XSS) vulnerabilities in photo_add-c.php (aka the "add comment" section) in WEBalbum 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) id, or (3) category parameter.    4.3  Medium  2017-01-03  2009-01-29  View
2597  CVE-2008-2699  Multiple directory traversal vulnerabilities in Galatolo WebManager (GWM) 1.0 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in (1) the plugin parameter to admin/plugins.php or (2) the com parameter to index.php.    7.5  High  2017-01-03  2009-04-08  View
2598  CVE-2008-2700  SQL injection vulnerability in view.php in Galatolo WebManager 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.    7.5  High  2017-01-03  2009-04-14  View
2599  CVE-2008-2701  SQL injection vulnerability in the GameQ (com_gameq) component 4.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a page action to index.php.    6.8  Medium  2017-01-03  2009-04-08  View
2600  CVE-2008-2702  Directory traversal vulnerability in the FTP client in ALTools ESTsoft ALFTP 4.1 beta 2 and 5.0 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code execution by writing to a Startup folder.    9.3  High  2017-01-03  2011-03-07  View

Page 520 of 17672, showing 5 records out of 88360 total, starting on record 2596, ending on 2600

Actions