NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
69587  CVE-2005-3949  Multiple SQL injection vulnerabilities in WebCalendar 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) startid parameter to activity_log.php, (2) startid parameter to admin_handler.php, (3) template parameter to edit_template.php, and (4) multiple parameters to export_handler.php.    7.5  High  2017-01-03  2011-03-07  View
4307  CVE-2008-4484  main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name parameter to "users," as demonstrated via index.php.    6.8  Medium  2017-01-03  2009-08-19  View
69843  CVE-2005-4245  Cross-site scripting (XSS) vulnerability in search.php in Snipe Gallery 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.    4.3  Medium  2017-01-03  2011-03-07  View
4563  CVE-2008-4749  Multiple insecure method vulnerabilities in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, allow remote attackers to overwrite arbitrary files via (1) the LogFile property and ClearLogFile method, and (2) the SaveToFile method.    9.3  High  2017-01-03  2009-01-29  View
70099  CVE-2005-4501  MediaWiki before 1.5.4 uses a hard-coded "internal placeholder string", which allows remote attackers to bypass protection against cross-site scripting (XSS) attacks and execute Javascript using inline style attributes, which are processed by Internet Explorer.    4.3  Medium  2017-01-03  2011-03-07  View

Page 14949 of 17672, showing 5 records out of 88360 total, starting on record 74741, ending on 74745

Actions