NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
3001 | CVE-2008-3117 | Unrestricted file upload vulnerability in update_profile.php in PHPmotion 2.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a .php file with a content type of (1) image/gif, (2) image/jpeg, or (3) image/pjpeg, then accessing it via a direct request to the file under pictures/. | 2 | 6.5 | Medium | 2017-01-03 | 2008-09-12 | View | |
3002 | CVE-2008-3118 | SQL injection vulnerability in play.php in PHPmotion 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the vid parameter. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
3003 | CVE-2008-3119 | SQL injection vulnerability in index.php in DreamPics Builder allows remote attackers to execute arbitrary SQL commands via the page parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-05-14 | View | |
3004 | CVE-2008-3120 | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-3363. Reason: This candidate is a duplicate of CVE-2008-3363. Notes: All CVE users should reference CVE-2008-3363 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. | 1 | 2017-01-03 | 2009-08-15 | View | |||
3005 | CVE-2008-3121 | Multiple cross-site scripting (XSS) vulnerabilities in Xerox CentreWare Web (CWW) before 4.6.46 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 601 of 17672, showing 5 records out of 88360 total, starting on record 3001, ending on 3005