NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
3001  CVE-2008-3117  Unrestricted file upload vulnerability in update_profile.php in PHPmotion 2.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a .php file with a content type of (1) image/gif, (2) image/jpeg, or (3) image/pjpeg, then accessing it via a direct request to the file under pictures/.    6.5  Medium  2017-01-03  2008-09-12  View
3002  CVE-2008-3118  SQL injection vulnerability in play.php in PHPmotion 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the vid parameter.    7.5  High  2017-01-03  2008-09-05  View
3003  CVE-2008-3119  SQL injection vulnerability in index.php in DreamPics Builder allows remote attackers to execute arbitrary SQL commands via the page parameter.    7.5  High  2017-01-03  2009-05-14  View
3004  CVE-2008-3120  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-3363. Reason: This candidate is a duplicate of CVE-2008-3363. Notes: All CVE users should reference CVE-2008-3363 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.        2017-01-03  2009-08-15  View
3005  CVE-2008-3121  Multiple cross-site scripting (XSS) vulnerabilities in Xerox CentreWare Web (CWW) before 4.6.46 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.    4.3  Medium  2017-01-03  2008-09-05  View

Page 601 of 17672, showing 5 records out of 88360 total, starting on record 3001, ending on 3005

Actions