NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
67595 | CVE-2005-1877 | Cross-site scripting (XSS) vulnerability in view_ticket.php in Lpanel 1.59 and earlier allows remote attackers to inject arbitrary web script or HTML and obtain sensitive information via the pid parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
2315 | CVE-2008-2399 | Directory traversal vulnerability in the FireFTP add-on before 0.98.20080518 for Firefox allows remote FTP servers to create or overwrite arbitrary files via .. (dot dot backslash) sequences in responses to (1) MLSD and (2) LIST commands, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code execution by writing to a Startup folder. | 2 | 9.3 | High | 2017-01-03 | 2011-03-07 | View | |
67851 | CVE-2005-2147 | Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer scripts. | 2 | 6.4 | Medium | 2017-01-03 | 2008-09-05 | View | |
2571 | CVE-2008-2673 | SQL injection vulnerability in index.php in Powie pNews 2.08 and 2.10, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the shownews parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-04-14 | View | |
68107 | CVE-2005-2416 | Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 1102 of 17672, showing 5 records out of 88360 total, starting on record 5506, ending on 5510