NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
70755 | CVE-2004-0304 | SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View | |
70754 | CVE-2004-0303 | OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
70753 | CVE-2004-0302 | Directory traversal vulnerability in OWLS 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter in index.php, (2) editfile in glossary.php, or (3) editfile in newmultiplechoice.php. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
70752 | CVE-2004-0301 | Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
70751 | CVE-2004-0300 | SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View |
Page 15970 of 17672, showing 5 records out of 88360 total, starting on record 79846, ending on 79850