NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
70535 | CVE-2004-0067 | Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8) calendar.php, (9) gedrecord.php, (10) login.php, and (11) gdbi_interface.php. NOTE: some aspects of vector 10 were later reported to affect 4.1. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
70534 | CVE-2004-0066 | phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (2) famlist.php, (3) placelist.php, (4) imageview.php, (5) timeline.php, (6) clippings.php, (7) login.php, and (8) gdbi.php. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
70533 | CVE-2004-0065 | Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2) placelist.php. | 2 | 7.5 | High | 2016-12-20 | 2016-10-17 | View | |
70532 | CVE-2004-0064 | The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlink attack on files within the tmp.SuSEconfig.gnome-filesystem.$RANDOM temporary directory. | 2 | 2.1 | Low | 2016-12-20 | 2016-10-17 | View | |
70531 | CVE-2004-0063 | The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause applications to make incorrect security-critical decisions, e.g. by accepting an invalid PIN number. | 2 | 7.5 | High | 2016-12-20 | 2016-10-17 | View |
Page 16014 of 17672, showing 5 records out of 88360 total, starting on record 80066, ending on 80070