NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 66897 | CVE-2005-1148 | calendar.pl in CalendarScript 3.21 allows remote attackers to obtain sensitive information via invalid (1) year or (2) month parameters, which leaks the full pathname and debug information. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 66896 | CVE-2005-1147 | calendar.pl in CalendarScript 3.20 allows remote attackers to obtain sensitive information via invalid (1) calendar or (2) template parameters, which leaks the full pathname and debug information. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 66895 | CVE-2005-1146 | ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in the login command in calendar.pl in CalendarScript 3.21 allows remote attackers to inject arbitrary web script or HTML via the username parameter, a different vulnerability than CVE-2005-1145. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 66894 | CVE-2005-1145 | ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in calendar.pl in CalendarScript 3.20 allows remote attackers to inject arbitrary web script or HTML via the template parameter, a different vulnerability than CVE-2005-1146. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
| 66893 | CVE-2005-1144 | popup.php in EasyPHPCalendar before 6.2.8 allows remote attackers to obtain sensitive information via an invalid ev parameter, which reveals the full pathname of the web server in a PHP error message. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 15270 of 17672, showing 5 records out of 88360 total, starting on record 76346, ending on 76350