NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
3651 | CVE-2008-3786 | Cross-site scripting (XSS) vulnerability in index.php in PICTURESPRO Photo Cart 3.9 allows remote attackers to inject arbitrary web script or HTML via the qtitle parameter (aka "Gallery or event name" field) in a search action. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
3652 | CVE-2008-3787 | SQL injection vulnerability in listing_view.php in Web Directory Script 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the name parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
3653 | CVE-2008-3788 | Multiple SQL injection vulnerabilities in PICTURESPRO Photo Cart 3.9, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) qtitle, (2) qid, and (3) qyear parameters to (a) search.php, and the (4) email and (5) password parameters to (b) _login.php. | 2 | 6.8 | Medium | 2017-01-03 | 2009-01-29 | View | |
3654 | CVE-2008-3789 | Samba 3.2.0 uses weak permissions (0666) for the (1) group_mapping.tdb and (2) group_mapping.ldb files, which allows local users to modify the membership of Unix groups. | 2 | 2.1 | Low | 2017-01-03 | 2011-03-07 | View | |
3655 | CVE-2008-3790 | The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through 1.8.7-p72, and 1.9 allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML document with recursively nested entities, aka an "XML entity explosion." | 2 | 5 | Medium | 2017-01-03 | 2011-03-07 | View |
Page 731 of 17672, showing 5 records out of 88360 total, starting on record 3651, ending on 3655