NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
66359 | CVE-2005-0607 | CubeCart 2.0.0 through 2.0.5 allows remote attackers to determine the full path of the server via direct calls without parameters to (1) information.php, (2) language.php, (3) list_docs.php, (4) popular_prod.php, (5) sale.php, (6) subfooter.inc.php, (7) subheader.inc.php, (8) cat_navi.php, or (9) check_sum.php, which reveals the path in a PHP error message. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
2615 | CVE-2008-2717 | TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote attackers to bypass security restrictions and upload configuration files such as .htaccess, or conduct file upload attacks using multiple extensions. | 2 | 6.5 | Medium | 2017-07-18 | 2017-07-11 | View | |
69175 | CVE-2005-3514 | Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Forum script allow remote attackers to inject arbitrary web script or HTML via the forumID parameter to (1) newtopic.php, (2) quote.php, (3) index.php, and (4) reply.php. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
69431 | CVE-2005-3793 | Multiple SQL injection vulnerabilities in AlstraSoft Affiliate Network Pro 7.2 allow remote attackers to bypass authentication and execute arbitrary SQL commands via the (1) username or (2) password to admin/admin_validate_login, or the (3) login, (4) password, and (5) flag parameters to login_validate.php. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
70711 | CVE-2004-0260 | The AddToMailingList function in CactuSoft CactuShop 5.0 Lite contains a backdoor that allows remote attackers to delete arbitrary files via an email address that starts with |||. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 16601 of 17672, showing 5 records out of 88360 total, starting on record 83001, ending on 83005