NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
6388 | CVE-2008-6657 | Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote attackers to hijack the authentication of admins for requests that install packages via the package parameter in an install2 action. | 2 | 6.8 | Medium | 2017-01-03 | 2009-07-23 | View | |
71924 | CVE-2004-1545 | UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
6644 | CVE-2008-6913 | Unrestricted file upload vulnerability in editresume_next.php in Zeeways ZEEJOBSITE 2.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a photo in a profile edit action, then accessing the file via a direct request to jobseekers/logos/. | 2 | 6.5 | Medium | 2017-01-03 | 2009-08-13 | View | |
72180 | CVE-2004-1801 | Directory traversal vulnerability in PWebServer 0.3.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
6900 | CVE-2008-7169 | SQL injection vulnerability in Jabode horoscope extension (com_jabode) for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a sign task to index.php. | 2 | 7.5 | High | 2017-01-03 | 2009-09-08 | View |
Page 16868 of 17672, showing 5 records out of 88360 total, starting on record 84336, ending on 84340