NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
80021 | CVE-2002-1025 | JRun 3.0 through 4.0 allows remote attackers to read JSP source code via an encoded null byte in an HTTP GET request, which causes the server to send the .JSP file unparsed. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
80789 | CVE-2002-1838 | Charities.cron 1.0.2 through 1.6.0 allows local users to write to arbitrary files via a symlink attack on temporary files. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
81045 | CVE-2002-2094 | Joe Testa hellbent 01 allows remote attackers to determine the full path of the web root directory via a GET request with a relative path that includes the root"s parent, which generates a 403 error message if the parent is incorrect, but a normal response if the parent is correct. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
81301 | CVE-2002-2350 | Cross-site scripting (XSS) vulnerability in z_user_show.php in dbtreelistproperty_method.php in Zorum 2.4 allows remote attackers to inject arbitrary web script or HTML via the class parameter. | 2 | 4.3 | Medium | 2017-01-05 | 2008-09-05 | View | |
54421 | CVE-2007-2254 | PHP remote file inclusion vulnerability in admin/setup/level2.php in PHP Classifieds 6.04, and probably earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: this product was referred to as "Allfaclassfieds" in the original disclosure. | 2 | 7.5 | High | 2017-01-07 | 2008-09-05 | View |
Page 1002 of 17672, showing 5 records out of 88360 total, starting on record 5006, ending on 5010