NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 69587 | CVE-2005-3949 | Multiple SQL injection vulnerabilities in WebCalendar 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) startid parameter to activity_log.php, (2) startid parameter to admin_handler.php, (3) template parameter to edit_template.php, and (4) multiple parameters to export_handler.php. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
| 4307 | CVE-2008-4484 | main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name parameter to "users," as demonstrated via index.php. | 2 | 6.8 | Medium | 2017-01-03 | 2009-08-19 | View | |
| 69843 | CVE-2005-4245 | Cross-site scripting (XSS) vulnerability in search.php in Snipe Gallery 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View | |
| 4563 | CVE-2008-4749 | Multiple insecure method vulnerabilities in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, allow remote attackers to overwrite arbitrary files via (1) the LogFile property and ClearLogFile method, and (2) the SaveToFile method. | 2 | 9.3 | High | 2017-01-03 | 2009-01-29 | View | |
| 70099 | CVE-2005-4501 | MediaWiki before 1.5.4 uses a hard-coded "internal placeholder string", which allows remote attackers to bypass protection against cross-site scripting (XSS) attacks and execute Javascript using inline style attributes, which are processed by Internet Explorer. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View |
Page 14949 of 17672, showing 5 records out of 88360 total, starting on record 74741, ending on 74745