NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
67048  CVE-2005-1309  Cross-site scripting (XSS) vulnerability in bBlog 0.7.4 allows remote attackers to inject arbitrary web script or HTML via the (1) entry title field or (2) comment body text.    4.3  Medium  2017-01-03  2008-09-05  View
67304  CVE-2005-1577  APG Technology ClassMaster does not properly restrict access to sensitive folders, which allows remote attackers to access folders via a network share.    7.5  High  2017-01-03  2008-09-05  View
68584  CVE-2005-2916  Linksys WRT54G 3.01.03, 3.03.6, 4.00.7, and possibly other versions before 4.20.7, does not verify user authentication until after an HTTP POST request has been processed, which allows remote attackers to (1) modify configuration using restore.cgi or (2) upload new firmware using upgrade.cgi.    Medium  2017-01-03  2008-09-05  View
69864  CVE-2005-4266  WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a username, which allows remote attackers to perform actions as other users by guessing or sniffing the random value.    7.5  High  2017-01-03  2008-09-05  View
70376  CVE-2005-4787  ** DISPUTED ** Turnkey Web Tools SunShop Shopping Cart allows remote attackers to obtain sensitive information via a phpinfo action to (1) index.php, (2) admin/index.php, and (3) admin/adminindex.php, which executes the PHP phpinfo function. NOTE: The vendor has disputed this issue, saying that "Having this in the code makes it easier for us to troubleshoot when issues arise on individual carts. For someone to have a script to do this type of search would require that they know where your shop is actually located. I dont think it really can be construde [sic] as a security issue."    Medium  2017-01-03  2008-09-05  View

Page 1523 of 17672, showing 5 records out of 88360 total, starting on record 7611, ending on 7615

Actions