NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 72330 | CVE-2004-1953 | phProfession 2.5 allows remote attackers to gain sensitive information via a direct HTTP request to upload.php, which reveals the path in a PHP error message. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72329 | CVE-2004-1952 | SQL injection vulnerability in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
| 72328 | CVE-2004-1951 | xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) audio.sun_audio_device or (2) dxr3.devicename options in an MRL link. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72327 | CVE-2004-1950 | phpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, which allows remote attackers to spoof IP addresses. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72326 | CVE-2004-1949 | SQL injection vulnerability in PostNuke 7.2.6 and earlier allows remote attackers to execute arbitrary SQL via (1) the sif parameter to index.php in the Comments module or (2) timezoneoffset parameter to changeinfo.php in the Your_Account module. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 15655 of 17672, showing 5 records out of 88360 total, starting on record 78271, ending on 78275