NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
70185 | CVE-2005-4596 | Cross-site scripting (XSS) vulnerability in read.php in AdesGuestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the totalRows_rsRead parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-20 | View | |
70441 | CVE-2005-4852 | The siteaccess URIMatching implementation in eZ publish 3.5 through 3.8 before 20050812 converts all non-alphanumeric characters in a URI to "_" (underscore), which allows remote attackers to bypass access restrictions by inserting certain characters in a URI, as demonstrated by a request for /admin:de, which matches a rule allowing only /admin_de to access /admin. | 2 | 5 | Medium | 2017-01-03 | 2015-07-28 | View | |
70953 | CVE-2004-0519 | Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
5673 | CVE-2008-5942 | Multiple cross-site scripting (XSS) vulnerabilities in MODx before 0.9.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the preserveUrls function and (2) "username input." NOTE: vector 2 may be related to CVE-2008-5939. | 2 | 4.3 | Medium | 2017-01-03 | 2009-02-05 | View | |
71721 | CVE-2004-1341 | Cross-site scripting (XSS) vulnerability in info2www before 1.2.2.9 allows remote attackers to inject arbitrary web script or HTML via the arguments to info2www. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 1490 of 17672, showing 5 records out of 88360 total, starting on record 7446, ending on 7450