NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
71805  CVE-2004-1426  Directory traversal vulnerability in index.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to read arbitrary files and execute arbitrary PHP files via .. (dot dot) sequences in the lng parameter.    Medium  2016-12-20  2016-10-17  View
71804  CVE-2004-1425  Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.    Medium  2017-07-18  2017-07-10  View
71803  CVE-2004-1424  Cross-site scripting (XSS) vulnerability in view.php in Moodle 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.    4.3  Medium  2017-07-18  2017-07-10  View
71802  CVE-2004-1423  Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Office (VLO) and other products, allow remote attackers to execute arbitrary PHP code via a URL in the phpc_root_path parameter to (1) includes/calendar.php or (2) includes/setup.php.    7.5  High  2017-07-18  2017-07-10  View
71801  CVE-2004-1422  WHM AutoPilot 2.4.6.5 and earlier allows remote attackers to gain sensitive information via phpinfo, which reveals php settings.    Medium  2017-07-18  2017-07-10  View

Page 15760 of 17672, showing 5 records out of 88360 total, starting on record 78796, ending on 78800

Actions