NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 71906 | CVE-2004-1527 | Microsoft Internet Explorer 6.0 SP1 does not properly handle certain character strings in the Path attribute, which can cause it to modify cookies in other domains when the attacker's domain name is within the target's domain name or when wildcard DNS is being used, which allows remote attackers to hijack web sessions. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 71907 | CVE-2004-1528 | The Event Calendar module 2.13 for PHP-Nuke allows remote attackers to gain sensitive information via an HTTP request to (1) config.php, (2) index.php, or (3) submit.php, which reveal the full path in an error message. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 71908 | CVE-2004-1529 | Cross-site scripting (XSS) vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary web script via the (1) type, (2) day, (3) month, or (4) year parameters in a Preview operation, or (5) event comments. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 71909 | CVE-2004-1530 | SQL injection vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the (1) eid or (2) cid parameters. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
| 71910 | CVE-2004-1531 | SQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL commands via the qpid parameter. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 14382 of 17672, showing 5 records out of 88360 total, starting on record 71906, ending on 71910