NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
3176  CVE-2008-3295  Cross-site scripting (XSS) vulnerability in modules/system/admin.php in XOOPS 2.0.18.1 allows remote attackers to inject arbitrary web script or HTML via the fct parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.    4.3  Medium  2017-01-03  2008-09-05  View
3177  CVE-2008-3296  Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the fct parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.    7.5  High  2017-01-03  2008-09-05  View
3178  CVE-2008-3297  Multiple SQL injection vulnerabilities in SocialEngine (SE) before 2.83 allow remote attackers to execute arbitrary SQL commands via (1) an se_user cookie to include/class_user.php or (2) an se_admin cookie to include/class_admin.php.    7.5  High  2017-01-03  2009-01-29  View
3179  CVE-2008-3298  SocialEngine (SE) before 2.83 grants certain write privileges for templates, which allows remote authenticated administrators to execute arbitrary PHP code.    Medium  2017-01-03  2009-01-29  View
3180  CVE-2008-3299  eSyndiCat 1.6 allows remote attackers to bypass authentication and gain administrative access by setting the admin_lng cookie value to 1. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.    7.5  High  2017-01-03  2008-09-10  View

Page 636 of 17672, showing 5 records out of 88360 total, starting on record 3176, ending on 3180

Actions