NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
44446  CVE-2012-2731  The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote attackers to obtain sensitive information by sniffing or reading the cache of the HTML of a webpage.    2.6  Low  2017-01-19  2012-06-27  View
55966  CVE-2007-3822  Multiple cross-site scripting (XSS) vulnerabilities in Webcit before 7.11 allow remote attackers to inject arbitrary web script or HTML via (1) the who parameter to showuser; and other vectors involving (2) calendar mode, (3) bulletin board mode, (4) room names, and (5) uploaded file names.    2.6  Low  2017-01-07  2008-11-15  View
68767  CVE-2005-3104  mt-comments.cgi in Movable Type before 3.2 allows attackers to redirect users to other web sites via URLs in comments.    2.6  Low  2017-01-03  2008-09-05  View
47263  CVE-2012-6582  Cross-site scripting (XSS) vulnerability in the Spambot module 6.x-3.x before 6.x-3.2 and 7.x-1.x before 7.x-1.1 for Drupal allows certain remote attackers to inject arbitrary web script or HTML via a stopforumspam.com API response, which is logged by the watchdog.    2.6  Low  2017-01-19  2013-08-21  View
65954  CVE-2005-0190  Directory traversal vulnerability in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to delete arbitrary files via a Real Metadata Packages (RMP) file with a FILENAME tag containing .. (dot dot) sequences in a filename that ends with a ? (question mark) and an allowed file extension (e.g. .mp3), which bypasses the check for the file extension.    2.6  Low  2017-07-18  2017-07-10  View

Page 15347 of 17672, showing 5 records out of 88360 total, starting on record 76731, ending on 76735

Actions