NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
81273 | CVE-2002-2322 | Ultimate PHP Board (UPB) 1.0b stores the users.dat data file under the web root with insufficient access control, which allows remote attackers to obtain usernames and passwords. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
54137 | CVE-2007-1967 | ** DISPUTED ** PHP remote file inclusion vulnerability in index.php in stat12 allows remote attackers to execute arbitrary PHP code via a URL in the langpath parameter. NOTE: this issue was published by an unreliable researcher, and there is little information to determine which product is actually affected. This is probably an invalid report based on analysis by CVE and a third party. | 2 | 6.8 | Medium | 2017-01-07 | 2008-09-05 | View | |
59513 | CVE-2006-0783 | Cross-site scripting (XSS) vulnerability in page.php in in Siteframe Beaumont, possibly 5.0.2 or 5.0.1a, allows remote attackers to inject arbitrary web script or HTML via the comment_text parameter to the user comment page (/edit/Comment). | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
60281 | CVE-2006-1573 | PHP remote file inclusion vulnerability in index.php in MediaSlash Gallery allows remote attackers to execute arbitrary PHP code via a URL in the rub parameter (part of the $page_menu variable). | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
60793 | CVE-2006-2088 | Multiple cross-site scripting (XSS) vulnerabilities in Devsyn Open Bulletin Board (OpenBB) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via (1) the FID parameter in board.php and (2) the TID parameter in read.php. NOTE: the SQL injection issues are already covered by CVE-2005-1612 (read.php) and CVE-2005-2566 (board.php). | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 16784 of 17672, showing 5 records out of 88360 total, starting on record 83916, ending on 83920