NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
11302 | CVE-2011-5042 | Cross-site scripting (XSS) vulnerability in inc/lib/lib.base.php in SASHA 0.2.0 allows remote attackers to inject arbitrary web script or HTML via the instructors parameter. NOTE: the original disclosure also mentions the section_title parameter, but this was disputed by the vendor and retracted by the original researcher. | 2 | 4.3 | Medium | 2017-01-07 | 2012-01-02 | View | |
11558 | CVE-2011-5306 | Cross-site request forgery (CSRF) vulnerability in cgi-bin/admin/setup_edit.cgi in CosmoShop ePRO 10.05.00 allows remote attackers to hijack the authentication of administrators for requests that modify settings via a setup action. | 2 | 6.8 | Medium | 2017-01-07 | 2015-01-02 | View | |
77094 | CVE-2000-0860 | The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
12070 | CVE-2010-0520 | Heap-based buffer overflow in QuickTimeAuthoring.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLC file, related to crafted DELTA_FLI chunks and untrusted length values in a .fli file, which are not properly handled during decompression. | 2 | 6.8 | Medium | 2017-01-18 | 2010-08-21 | View | |
12326 | CVE-2010-0787 | client/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3, 3.3.2, 3.4.0, and 3.4.5 allows local users to mount a CIFS share on an arbitrary mountpoint, and gain privileges, via a symlink attack on the mountpoint directory file. | 2 | 4.4 | Medium | 2017-01-18 | 2013-04-18 | View |
Page 1388 of 17672, showing 5 records out of 88360 total, starting on record 6936, ending on 6940