NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
67662  CVE-2005-1947  Cross-site request forgery (CSRF) vulnerability in Invision Gallery before 1.3.1 allows remote attackers to delete albums and images as another user via a link or IMG tag to the (1) albums or (2) delimg actions.    Medium  2017-01-03  2016-10-17  View
67661  CVE-2005-1946  Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to an editentry, replyentry, or editcomment action, or (2) the mid parameter to an aboutme action.    7.5  High  2017-01-03  2016-10-17  View
67660  CVE-2005-1945  Cross-site scripting (XSS) vulnerability in the convert_highlite_words function in Invision Blog before 1.1.2 Final allows remote attackers to inject arbitrary web script or HTML via double hex encoded highlight data.    4.3  Medium  2017-01-03  2016-10-17  View
67659  CVE-2005-1944  xmysqladmin 1.0 and earlier allows local users to delete arbitrary files via a symlink attack on a database backup file in /tmp.    2.1  Low  2017-01-03  2016-10-17  View
67658  CVE-2005-1943  Multiple SQL injection vulnerabilities in Loki download manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) password field to default.asp or (2) cat parameter to catinfo.asp.    7.5  High  2017-01-03  2016-10-17  View

Page 15117 of 17672, showing 5 records out of 88360 total, starting on record 75581, ending on 75585

Actions