NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
72310  CVE-2004-1933  Citadel/UX 5.00 through 6.14 installs the database directory and files with world-read permissions, which could allow local users to bypass access controls and read unauthorized messages.    2.1  Low  2017-07-18  2017-07-10  View
72309  CVE-2004-1932  SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL code and create an administrator account via base64-encoded SQL in the admin parameter.    7.5  High  2017-07-18  2017-07-10  View
72308  CVE-2004-1930  Cross-site scripting (XSS) vulnerability in the cookiedecode function in mainfile.php for PHP-Nuke 6.x through 7.2, when themes are used, allows remote attackers to inject arbitrary web script or HTML via a base64-encoded user parameter or cookie.    4.3  Medium  2017-07-18  2017-07-10  View
72307  CVE-2004-1929  SQL injection vulnerability in the bblogin function in functions.php in PHP-Nuke 6.x through 7.2 allows remote attackers to bypass authentication and gain access by injecting base64-encoded SQL code into the user parameter.    7.5  High  2017-07-18  2017-07-10  View
72306  CVE-2004-1928  The image upload feature in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to upload and possibly execute arbitrary files via the img/wiki_up URL.    7.5  High  2017-07-18  2017-07-10  View

Page 15659 of 17672, showing 5 records out of 88360 total, starting on record 78291, ending on 78295

Actions