NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
426  CVE-2008-0448  PHP remote file inclusion vulnerability in utils/class_HTTPRetriever.php in phpSearch allows remote attackers to execute arbitrary PHP code via a URL in the libcurlemuinc parameter.    7.5  High  2017-01-03  2008-09-05  View
65962  CVE-2005-0198  A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce all the required conditions for successful authentication, which allows remote attackers to authenticate as arbitrary users.    7.5  High  2017-01-03  2010-08-21  View
66986  CVE-2005-1240  Directory traversal vulnerability in the third party tool from Castlehill, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request.    7.5  High  2017-07-18  2017-07-10  View
2218  CVE-2008-2297  The admin.php file in Rantx allows remote attackers to bypass authentication and gain privileges by setting the logininfo cookie to "<?php" or "?>", which is present in the password file and probably passes an insufficient comparison.    7.5  High  2017-01-03  2008-09-05  View
67754  CVE-2005-2045  Multiple SQL injection vulnerabilities in DUware DUportal PRO 3.4.3 allow remote attackers to execute arbitrary SQL commands via the (1) iChannel parameter to default.asp, (2) iData parameter to detail.asp, (3) iMem parameter to members.asp, (4) iCat parameter to cat.asp, (5) offset parameter to members_listing_approval.asp, or (6) iChannel parameter to channels_edit.asp.    7.5  High  2017-01-03  2016-10-17  View

Page 14728 of 17672, showing 5 records out of 88360 total, starting on record 73636, ending on 73640

Actions