NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
71888  CVE-2004-1509  validate.php in WebCalendar allows remote attackers to gain sensitive information via an invalid encoded_login parameter, which reveals the full path in an error message.    Medium  2017-07-18  2017-07-10  View
72144  CVE-2004-1765  Off-by-one buffer overflow in ModSecurity (mod_security) 1.7.4 for Apache 2.x, when SecFilterScanPost is enabled, allows remote attackers to execute arbitrary code via crafted POST requests.    7.5  High  2017-07-18  2017-07-10  View
72400  CVE-2004-2023  SQL injection vulnerability in login.php in Zen Cart 1.1.2d, 1.1.4 before patch 1, and possibly other versions allows remote attackers to execute arbitrary SQL via the (1) admin_name or (2) admin_pass parameters.    7.5  High  2017-07-18  2017-07-10  View
72656  CVE-2004-2279  Cross-site scripting (XSS) vulnerability in Invision Power Board 1.3 Final allows remote attackers to execute arbitrary script as other users via the pop parameter in a chat action to index.php.    4.3  Medium  2017-07-18  2017-07-10  View
72912  CVE-2004-2535  The person-to-person secure messaging feature in Sticker before 3.1.0 beta 2 allows remote attackers to post messages to unauthorized private groups by using the group's public encryption key.    Medium  2017-07-18  2017-07-10  View

Page 1044 of 17672, showing 5 records out of 88360 total, starting on record 5216, ending on 5220

Actions