NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
8565  CVE-2011-1671  Cross-site scripting (XSS) vulnerability in app/controllers/todos_controller.rb in Tracks 1.7.2, 2.0RC2, and 2.0devel allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to todos/tag/. NOTE: some of these details are obtained from third party information.    4.3  Medium  2017-01-07  2011-09-21  View
8564  CVE-2011-1670  Cross-site scripting (XSS) vulnerability in actions/add.php in InTerra Blog Machine 1.84, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the subject parameter to post_url/edit.    4.3  Medium  2017-01-07  2011-09-21  View
8563  CVE-2011-1669  Directory traversal vulnerability in wp-download.php in the WP Custom Pages module 0.5.0.1 for WordPress allows remote attackers to read arbitrary files via ..%2F (encoded dot dot) sequences in the url parameter.    Medium  2017-01-07  2011-10-13  View
8562  CVE-2011-1668  Cross-site scripting (XSS) vulnerability in search.php in AR Web Content Manager (AWCM) 2.1, 2.2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the search parameter.    4.3  Medium  2017-01-07  2011-09-21  View
8561  CVE-2011-1667  SQL injection vulnerability in index.php in Anzeigenmarkt 2011 allows remote attackers to execute arbitrary SQL commands via the q parameter in a list action.    7.5  High  2017-01-07  2011-09-21  View

Page 15960 of 17672, showing 5 records out of 88360 total, starting on record 79796, ending on 79800

Actions