NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
3236 | CVE-2008-3355 | SQL injection vulnerability in sitemap.xml.php in Camera Life 2.6.2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a photos action. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
3237 | CVE-2008-3356 | verifydb in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and other Unix platforms sets the ownership or permissions of an iivdb.log file without verifying that it is the application"s own log file, which allows local users to overwrite arbitrary files by creating a symlink with an iivdb.log filename. | 2 | 4.6 | Medium | 2017-01-03 | 2011-03-07 | View | |
3238 | CVE-2008-3357 | Untrusted search path vulnerability in ingvalidpw in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and HP-UX allows local users to gain privileges via a crafted shared library, related to a "pointer overwrite vulnerability." | 2 | 7.2 | High | 2017-01-03 | 2011-03-07 | View | |
3239 | CVE-2008-3358 | Cross-site scripting (XSS) vulnerability in Web Dynpro (WD) in the SAP NetWeaver portal, when Internet Explorer 7.0.5730 is used, allows remote attackers to inject arbitrary web script or HTML via a crafted URI, which causes the XSS payload to be reflected in a text/plain document. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View | |
3240 | CVE-2008-3359 | SQL injection vulnerability in register.php in Steve Bourgeois and Chris Vincent Owl Intranet Knowledgebase 0.95 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View |
Page 648 of 17672, showing 5 records out of 88360 total, starting on record 3236, ending on 3240