NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
66301  CVE-2005-0544  phpMyAdmin 2.6.1 allows remote attackers to obtain the full path of the server via direct requests to (1) sqlvalidator.lib.php, (2) sqlparser.lib.php, (3) select_theme.lib.php, (4) select_lang.lib.php, (5) relation_cleanup.lib.php, (6) header_meta_style.inc.php, (7) get_foreign.lib.php, (8) display_tbl_links.lib.php, (9) display_export.lib.php, (10) db_table_exists.lib.php, (11) charset_conversion.lib.php, (12) ufpdf.php, (13) mysqli.dbi.lib.php, (14) setup.php, or (15) cookie.auth.lib.php, which reveals the path in a PHP error message.    Medium  2017-01-03  2008-09-05  View
1021  CVE-2008-1060  Eval injection vulnerability in modules/execute.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary PHP code via the text parameter.    7.5  High  2017-01-03  2008-09-05  View
1277  CVE-2008-1318  Unspecified vulnerability in MediaWiki 1.11 before 1.11.2 allows remote attackers to obtain sensitive "cross-site" information via the callback parameter in an API call for JavaScript Object Notation (JSON) formatted results.    Medium  2017-01-03  2011-04-18  View
66813  CVE-2005-1064  The copy_symlink function in rsnapshot 1.2.0 and 1.1.x before 1.1.7 changes the ownership of files that a symlink points to rather than the symlink itself, which allows local users to obtain access to arbitrary files.    4.6  Medium  2017-01-03  2016-10-17  View
1533  CVE-2008-1590  JavaScriptCore in WebKit on Apple iPhone before 2.0 and iPod touch before 2.0 does not properly perform runtime garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger memory corruption, a different vulnerability than CVE-2008-2317.    6.8  Medium  2017-01-03  2011-03-07  View

Page 16146 of 17672, showing 5 records out of 88360 total, starting on record 80726, ending on 80730

Actions