NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
78701 | CVE-2001-1266 | Directory traversal vulnerability in Doug Neal"s HTTPD Daemon (DNHTTPD) before 0.4.1 allows remote attackers to view arbitrary files via a .. (dot dot) attack using the dot hex code "%2E". | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
78957 | CVE-2001-1526 | Cross-site scripting (XSS) vulnerability in the comments action in index.php in easyNews 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the zeit parameter. | 2 | 4.3 | Medium | 2017-01-05 | 2008-09-05 | View | |
79469 | CVE-2002-0463 | home.php in ARSC (Really Simple Chat) 1.0.1 and earlier allows remote attackers to determine the full pathname of the web server via an invalid language in the arsc_language parameter, which leaks the pathname in an error message. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
80749 | CVE-2002-1798 | MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or (2) access sensitive information via a direct request to admin/credit_card_info.php. | 2 | 6.4 | Medium | 2017-01-05 | 2008-09-05 | View | |
81261 | CVE-2002-2310 | ClickCartPro 4.0 stores the admin_user.db data file under the web document root with insufficient access control on servers other than Apache, which allows remote attackers to obtain usernames and passwords. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View |
Page 16689 of 17672, showing 5 records out of 88360 total, starting on record 83441, ending on 83445