NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
72035  CVE-2004-1656  CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the redirecturl parameter.    Medium  2017-07-18  2017-07-10  View
72034  CVE-2004-1655  Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) CM_pid parameter in the comments module or (2) the subject or message fields in the notes module.    4.3  Medium  2017-07-18  2017-07-10  View
72033  CVE-2004-1654  SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows remote attackers to execute arbitrary SQL commands via cal_template.    7.5  High  2017-07-18  2017-07-10  View
72032  CVE-2004-1653  The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port bounce, when configured with an anonymous access program such as AnonCVS.    6.4  Medium  2017-07-18  2017-07-10  View
72031  CVE-2004-1652  phpScheduleIt 1.0.0 RC1 does not clear administrative privileges if the administrator logs in as a normal user, which allows users with physical access to gain administrative privileges.    7.5  High  2017-07-18  2017-07-10  View

Page 15714 of 17672, showing 5 records out of 88360 total, starting on record 78566, ending on 78570

Actions