NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
2771 | CVE-2008-2877 | PHP remote file inclusion vulnerability in admin/include/lib.module.php in cmsWorks 2.2 RC4, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mod_root parameter. | 2 | 6.8 | Medium | 2017-01-03 | 2008-09-05 | View | |
4051 | CVE-2008-4195 | Opera before 9.52 does not properly restrict the ability of a framed web page to change the address associated with a different frame, which allows remote attackers to trigger the display of an arbitrary address in a frame via unspecified use of web script. | 2 | 5 | Medium | 2017-01-03 | 2012-06-08 | View | |
4307 | CVE-2008-4484 | main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name parameter to "users," as demonstrated via index.php. | 2 | 6.8 | Medium | 2017-01-03 | 2009-08-19 | View | |
69843 | CVE-2005-4245 | Cross-site scripting (XSS) vulnerability in search.php in Snipe Gallery 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View | |
70099 | CVE-2005-4501 | MediaWiki before 1.5.4 uses a hard-coded "internal placeholder string", which allows remote attackers to bypass protection against cross-site scripting (XSS) attacks and execute Javascript using inline style attributes, which are processed by Internet Explorer. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View |
Page 16073 of 17672, showing 5 records out of 88360 total, starting on record 80361, ending on 80365