NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 44446 | CVE-2012-2731 | The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote attackers to obtain sensitive information by sniffing or reading the cache of the HTML of a webpage. | 2 | 2.6 | Low | 2017-01-19 | 2012-06-27 | View | |
| 55966 | CVE-2007-3822 | Multiple cross-site scripting (XSS) vulnerabilities in Webcit before 7.11 allow remote attackers to inject arbitrary web script or HTML via (1) the who parameter to showuser; and other vectors involving (2) calendar mode, (3) bulletin board mode, (4) room names, and (5) uploaded file names. | 2 | 2.6 | Low | 2017-01-07 | 2008-11-15 | View | |
| 68767 | CVE-2005-3104 | mt-comments.cgi in Movable Type before 3.2 allows attackers to redirect users to other web sites via URLs in comments. | 2 | 2.6 | Low | 2017-01-03 | 2008-09-05 | View | |
| 47263 | CVE-2012-6582 | Cross-site scripting (XSS) vulnerability in the Spambot module 6.x-3.x before 6.x-3.2 and 7.x-1.x before 7.x-1.1 for Drupal allows certain remote attackers to inject arbitrary web script or HTML via a stopforumspam.com API response, which is logged by the watchdog. | 2 | 2.6 | Low | 2017-01-19 | 2013-08-21 | View | |
| 65954 | CVE-2005-0190 | Directory traversal vulnerability in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to delete arbitrary files via a Real Metadata Packages (RMP) file with a FILENAME tag containing .. (dot dot) sequences in a filename that ends with a ? (question mark) and an allowed file extension (e.g. .mp3), which bypasses the check for the file extension. | 2 | 2.6 | Low | 2017-07-18 | 2017-07-10 | View |
Page 15347 of 17672, showing 5 records out of 88360 total, starting on record 76731, ending on 76735