NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
71805 | CVE-2004-1426 | Directory traversal vulnerability in index.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to read arbitrary files and execute arbitrary PHP files via .. (dot dot) sequences in the lng parameter. | 2 | 5 | Medium | 2016-12-20 | 2016-10-17 | View | |
71804 | CVE-2004-1425 | Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
71803 | CVE-2004-1424 | Cross-site scripting (XSS) vulnerability in view.php in Moodle 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
71802 | CVE-2004-1423 | Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Office (VLO) and other products, allow remote attackers to execute arbitrary PHP code via a URL in the phpc_root_path parameter to (1) includes/calendar.php or (2) includes/setup.php. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
71801 | CVE-2004-1422 | WHM AutoPilot 2.4.6.5 and earlier allows remote attackers to gain sensitive information via phpinfo, which reveals php settings. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 15760 of 17672, showing 5 records out of 88360 total, starting on record 78796, ending on 78800