NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
2596 | CVE-2008-2698 | Multiple cross-site scripting (XSS) vulnerabilities in photo_add-c.php (aka the "add comment" section) in WEBalbum 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) id, or (3) category parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2009-01-29 | View | |
2597 | CVE-2008-2699 | Multiple directory traversal vulnerabilities in Galatolo WebManager (GWM) 1.0 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in (1) the plugin parameter to admin/plugins.php or (2) the com parameter to index.php. | 2 | 7.5 | High | 2017-01-03 | 2009-04-08 | View | |
2598 | CVE-2008-2700 | SQL injection vulnerability in view.php in Galatolo WebManager 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-04-14 | View | |
2599 | CVE-2008-2701 | SQL injection vulnerability in the GameQ (com_gameq) component 4.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a page action to index.php. | 2 | 6.8 | Medium | 2017-01-03 | 2009-04-08 | View | |
2600 | CVE-2008-2702 | Directory traversal vulnerability in the FTP client in ALTools ESTsoft ALFTP 4.1 beta 2 and 5.0 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code execution by writing to a Startup folder. | 2 | 9.3 | High | 2017-01-03 | 2011-03-07 | View |
Page 520 of 17672, showing 5 records out of 88360 total, starting on record 2596, ending on 2600