NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 67662 | CVE-2005-1947 | Cross-site request forgery (CSRF) vulnerability in Invision Gallery before 1.3.1 allows remote attackers to delete albums and images as another user via a link or IMG tag to the (1) albums or (2) delimg actions. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View | |
| 67661 | CVE-2005-1946 | Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to an editentry, replyentry, or editcomment action, or (2) the mid parameter to an aboutme action. | 2 | 7.5 | High | 2017-01-03 | 2016-10-17 | View | |
| 67660 | CVE-2005-1945 | Cross-site scripting (XSS) vulnerability in the convert_highlite_words function in Invision Blog before 1.1.2 Final allows remote attackers to inject arbitrary web script or HTML via double hex encoded highlight data. | 2 | 4.3 | Medium | 2017-01-03 | 2016-10-17 | View | |
| 67659 | CVE-2005-1944 | xmysqladmin 1.0 and earlier allows local users to delete arbitrary files via a symlink attack on a database backup file in /tmp. | 2 | 2.1 | Low | 2017-01-03 | 2016-10-17 | View | |
| 67658 | CVE-2005-1943 | Multiple SQL injection vulnerabilities in Loki download manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) password field to default.asp or (2) cat parameter to catinfo.asp. | 2 | 7.5 | High | 2017-01-03 | 2016-10-17 | View |
Page 15117 of 17672, showing 5 records out of 88360 total, starting on record 75581, ending on 75585