NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
71536 | CVE-2004-1146 | Multiple cross-site scripting (XSS) vulnerabilities in (1) main.c and (2) login.c for CVSTrac before 1.1.5 allow remote attackers to inject arbitrary HTML and web script. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
71792 | CVE-2004-1413 | Multiple SQL injection vulnerabilities in Kayako eSupport 2.x allow remote attackers to execute arbitrary SQL commands via the (1) subcat, (2) rate, (3) questiondetails, (4) ticketkey22, (5) email22 parameters to index.php, or (6) the e-mail field of the Forgot Key feature. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
72048 | CVE-2004-1669 | Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to execute arbitrary web script or HTML via the (1) User name parameter to accountsettings.html or (2) Search string parameter to search.html. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
72816 | CVE-2004-2439 | The remote upgrade capability in HP LaserJet 4200 and 4300 printers does not require a password, which allows remote attackers to upgrade firmware. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
73584 | CVE-2003-0456 | VisNetic WebSite 3.5 allows remote attackers to obtain the full pathname of the server via a request containing a folder that does not exist, which leaks the pathname in an error message, as demonstrated using _vti_bin/fpcount.exe. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 16875 of 17672, showing 5 records out of 88360 total, starting on record 84371, ending on 84375