NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
71890 | CVE-2004-1511 | Hotfoon 4.0 does not notify users before opening links in web browsers, which could allow remote attackers to execute arbitrary code via a certain link sent in a chat window. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
71889 | CVE-2004-1510 | WebCalendar allows remote attackers to gain privileges by modifying critical parameters to (1) view_entry.php or (2) upcoming.php. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
71888 | CVE-2004-1509 | validate.php in WebCalendar allows remote attackers to gain sensitive information via an invalid encoded_login parameter, which reveals the full path in an error message. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
71887 | CVE-2004-1508 | init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
71886 | CVE-2004-1507 | CRLF injection vulnerability in login.php in WebCalendar allows remote attackers to inject CRLF sequences via the return_path parameter and perform HTTP Response Splitting attacks to modify expected HTML content from the server. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 15743 of 17672, showing 5 records out of 88360 total, starting on record 78711, ending on 78715