NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
68999 | CVE-2005-3337 | Multiple cross-site scripting (XSS) vulnerabilities in Mantis before 0.19.3 allow remote attackers to inject arbitrary web script or HTML via (1) unknown vectors involving Javascript and (2) mantis/view_all_set.php. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
69767 | CVE-2005-4159 | ** DISPUTED ** NOTE: this issue has been disputed by the vendor and third parties. SQL injection vulnerability in Memberlist.php in Simple Machines Forum (SMF) 1.1 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter. NOTE: the vendor says that since only one character can be modified, there is no SQL injection. Thus this might be an "invalid SQL syntax error." Multiple followups support the vendor. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
70279 | CVE-2005-4690 | Six Apart Movable Type 3.16 allows local users with blog-creation privileges to create or overwrite arbitrary files of certain types (such as HTML and image files) by selecting an arbitrary directory as a blog"s top-level directory. NOTE: this issue can be used in conjunction with CVE-2005-3102 to create or overwrite arbitrary files of all types. | 2 | 2.1 | Low | 2017-01-03 | 2008-09-05 | View | |
73095 | CVE-2004-2718 | PHPMyChat 0.14.5 does not remove or protect setup.php3 after installation, which allows attackers to obtain sensitive information including database passwords via a direct request. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
74375 | CVE-2003-1305 | Microsoft Internet Explorer allows remote attackers to cause a denial of service (resource consumption) via a Javascript src attribute that recursively loads the current web page. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 16878 of 17672, showing 5 records out of 88360 total, starting on record 84386, ending on 84390