NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 68572 | CVE-2005-2897 | WEB//NEWS 1.4 allows remote attackers to obtain sensitive information via a direct request to files in the actions directory, which reveal the path in an error message, as demonstrated using cat.add.php. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View | |
| 68571 | CVE-2005-2896 | SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_userpw parameter to startup.php, (2) cat, (3) id, or (4) stof parameter to news.php, or (5) id parameter to print.php. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
| 68570 | CVE-2005-2895 | setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to obtain sensitive information via a %00 (a null byte) in the u parameter, which reveals the path in an error message. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 68569 | CVE-2005-2894 | Cross-site scripting (XSS) vulnerability in the user registration in PBLang 4.65, and possibly earlier versions, allows remote attackers to inject arbitrary web script or PHP via the location field. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 68568 | CVE-2005-2893 | Direct static code injection vulnerability in setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via the username (u parameter), which is directly injected into a file that is later executed upon login. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 14935 of 17672, showing 5 records out of 88360 total, starting on record 74671, ending on 74675