NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
64075 | CVE-2006-5474 | The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access as an arbitrary user by requesting a password reset. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
64843 | CVE-2006-6282 | members.php in Vikingboard 0.1.2 allows remote attackers to trigger a forced SQL error via an invalid s parameter, a different vector than CVE-2006-4709. NOTE: might only be an exposure if display_errors is enabled, but due to lack of details, even this is not clear. | 2 | 9.3 | High | 2016-12-20 | 2008-09-05 | View | |
588 | CVE-2008-0613 | Open redirect vulnerability in htdocs/user.php in XOOPS 2.0.18 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the xoops_redirect parameter. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
844 | CVE-2008-0873 | SQL injection vulnerability in index.php in the jlmZone Classifieds module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in an Adsview action. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
66636 | CVE-2005-0886 | Cross-site scripting (XSS) vulnerability in Invision Power Board 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an HTTP POST request. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 16454 of 17672, showing 5 records out of 88360 total, starting on record 82266, ending on 82270