NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 5858 | CVE-2008-6127 | Multiple cross-site scripting (XSS) vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) page and (2) query parameters to (a) index.php, (3) cat and (4) file parameters to (b) download.php, (5) gal parameter to gallery.php, and the (6) URL to admin/login.php. | 2 | 4.3 | Medium | 2017-01-03 | 2009-08-19 | View | |
| 71394 | CVE-2004-0992 | Format string vulnerability in the -a option (daemon mode) in Proxytunnel before 1.2.3 allows remote attackers to execute arbitrary code via format string specifiers in an invalid proxy answer. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View | |
| 6114 | CVE-2008-6383 | SQL injection vulnerability in SpeedTech Organization and Resource Manager (Storm) 5.x before 5.x-1.14 and 6.x before 6.x-1.18, a module for Drupal, allows remote authenticated users with storm project access to execute arbitrary SQL commands via unspecified vectors. | 2 | 6 | Medium | 2017-01-03 | 2009-05-14 | View | |
| 71650 | CVE-2004-1270 | lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows local users to control output to passwd.new via certain user input that triggers an error message. | 2 | 2.1 | Low | 2017-07-18 | 2017-07-10 | View | |
| 6370 | CVE-2008-6639 | Cross-site request forgery (CSRF) vulnerability in admin.php in AjaXplorer 2.3.3 and 2.3.4 allows remote attackers to hijack the authentication of administrators for requests that modify passwords via the update_user_pwd action. | 2 | 6.8 | Medium | 2017-01-03 | 2009-04-07 | View |
Page 15642 of 17672, showing 5 records out of 88360 total, starting on record 78206, ending on 78210