NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 68472 | CVE-2005-2785 | cosmoshop 8.10.78 and earlier stores passwords in plaintext in the database, which allows local users to obtain sensitive information. | 2 | 2.1 | Low | 2017-07-18 | 2017-07-10 | View | |
| 68471 | CVE-2005-2784 | SQL injection vulnerability in the login function for the administration login panel in cosmoshop 8.10.78 allows remote attackers to execute arbitrary SQL commands and bypass authentication via unspecified vectors. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
| 68470 | CVE-2005-2783 | Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML via nested, malformed URL BBCode tags. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 68469 | CVE-2005-2782 | PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an "ftp://" URL in the alpath parameter, which bypasses the incomplete blacklist that only checks for "http" and "https" URLs. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
| 68468 | CVE-2005-2781 | The Avatar upload feature in FUD Forum before 2.7.0 does not properly verify uploaded files, which allows remote attackers to execute arbitrary PHP code via a file with a .php extension that contains image data followed by PHP code. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 14955 of 17672, showing 5 records out of 88360 total, starting on record 74771, ending on 74775