NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
2866 | CVE-2008-2972 | SQL injection vulnerability in index.php in KbLance allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a comment action. | 2 | 7.5 | High | 2017-01-03 | 2009-01-14 | View | |
2867 | CVE-2008-2973 | Multiple cross-site scripting (XSS) vulnerabilities in chathead.php in MM Chat 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) sitename and (2) wmessage parameters. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-14 | View | |
2868 | CVE-2008-2974 | Directory traversal vulnerability in chatconfig.php in MM Chat 1.5, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the currentlang parameter. | 2 | 6.8 | Medium | 2017-01-03 | 2009-04-08 | View | |
2869 | CVE-2008-2975 | Cross-site scripting (XSS) vulnerability in admin/objects/obj_image.php in TinX/cms 1.1 allows remote attackers to inject arbitrary web script or HTML via the language parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
2870 | CVE-2008-2976 | Multiple directory traversal vulnerabilities in TinX/cms 1.1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) language parameter to (a) include_me.php, (b) admin/ajax.php, and (c) admin/objects/catalog.ajaxhandler.php; and the (2) prefix parameter to (d) admin/inc/config.php. | 2 | 6.8 | Medium | 2017-01-03 | 2009-04-14 | View |
Page 574 of 17672, showing 5 records out of 88360 total, starting on record 2866, ending on 2870