NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
4446 | CVE-2008-4632 | Multiple directory traversal vulnerabilities in index.php in Kure 0.6.3, when magic_quotes_gpc is disabled, allow remote attackers to read and possibly execute arbitrary local files via a .. (dot dot) in the (1) post and (2) doc parameters. | 2 | 6.8 | Medium | 2017-01-03 | 2009-01-29 | View | |
4447 | CVE-2008-4633 | SQL injection vulnerability in Node Vote 5.x before 5.x-1.1 and 6.x before 6.x-1.0, a module for Drupal, when "Allow user to vote again" is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to a "previously cast vote." | 2 | 6 | Medium | 2017-01-03 | 2008-10-21 | View | |
4448 | CVE-2008-4634 | Cross-site scripting (XSS) vulnerability in Movable Type 4 through 4.21 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to the administrative page, a different vulnerability than CVE-2008-4079. | 2 | 3.5 | Low | 2017-01-03 | 2009-07-22 | View | |
4449 | CVE-2008-4635 | Unspecified vulnerability in Hisanaga Electric Co, Ltd. hisa_cart 1.29 and earlier, a module for XOOPS, allows remote attackers to obtain sensitive user information via unknown vectors. | 2 | 5 | Medium | 2017-01-03 | 2009-07-22 | View | |
4450 | CVE-2008-4636 | yast2-backup 2.14.2 through 2.16.6 on SUSE Linux and Novell Linux allows local users to gain privileges via shell metacharacters in filenames used by the backup process. | 2 | 7.2 | High | 2017-01-03 | 2008-12-03 | View |
Page 890 of 17672, showing 5 records out of 88360 total, starting on record 4446, ending on 4450