NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
4826 | CVE-2008-5039 | Cross-site scripting (XSS) vulnerability in the League module for PHP-Nuke, possibly 2.4, allows remote attackers to inject arbitrary web script or HTML via the tid parameter in a team action to modules.php. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-30 | View | |
4827 | CVE-2008-5040 | Graphiks MyForum 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the (1) myforum_login and (2) myforum_pass cookies to 1. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
4828 | CVE-2008-5041 | Sweex RO002 Router with firmware Ts03-072 has "rdc123" as its default password for the "rdc123" account, which makes it easier for remote attackers to obtain access. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 7.5 | High | 2017-01-03 | 2012-10-30 | View | |
4829 | CVE-2008-5042 | Zeeways PhotoVideoTube 1.1 and earlier allows remote attackers to bypass authentication and perform administrative tasks via a direct request to admin/home.php. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
4830 | CVE-2008-5043 | Multiple cross-site scripting (XSS) vulnerabilities in the web-based interface in IBM Metrica Service Assurance Framework allow remote authenticated users to inject arbitrary web script or HTML via (1) the elementid parameter in a generatedreportresults action to the ReportTree program, (2) the jnlpname parameter to the Launch program, or (3) the :tasklabel parameter to the ReportRequest program, related to the name of a report. | 2 | 3.5 | Low | 2017-01-03 | 2012-10-30 | View |
Page 966 of 17672, showing 5 records out of 88360 total, starting on record 4826, ending on 4830