NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
8565 | CVE-2011-1671 | Cross-site scripting (XSS) vulnerability in app/controllers/todos_controller.rb in Tracks 1.7.2, 2.0RC2, and 2.0devel allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to todos/tag/. NOTE: some of these details are obtained from third party information. | 2 | 4.3 | Medium | 2017-01-07 | 2011-09-21 | View | |
8564 | CVE-2011-1670 | Cross-site scripting (XSS) vulnerability in actions/add.php in InTerra Blog Machine 1.84, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the subject parameter to post_url/edit. | 2 | 4.3 | Medium | 2017-01-07 | 2011-09-21 | View | |
8563 | CVE-2011-1669 | Directory traversal vulnerability in wp-download.php in the WP Custom Pages module 0.5.0.1 for WordPress allows remote attackers to read arbitrary files via ..%2F (encoded dot dot) sequences in the url parameter. | 2 | 5 | Medium | 2017-01-07 | 2011-10-13 | View | |
8562 | CVE-2011-1668 | Cross-site scripting (XSS) vulnerability in search.php in AR Web Content Manager (AWCM) 2.1, 2.2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the search parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2011-09-21 | View | |
8561 | CVE-2011-1667 | SQL injection vulnerability in index.php in Anzeigenmarkt 2011 allows remote attackers to execute arbitrary SQL commands via the q parameter in a list action. | 2 | 7.5 | High | 2017-01-07 | 2011-09-21 | View |
Page 15960 of 17672, showing 5 records out of 88360 total, starting on record 79796, ending on 79800