NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
70389 | CVE-2005-4800 | Direct static code injection vulnerability in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allows remote authenticated administrators to inject arbitrary PHP code via the TestGallery parameter in a mod_info action to modify_gallery.php, which inserts the code into guid_info.php. NOTE: this issue is easier to exploit due to a separate CSRF vulnerability. | 2 | 9 | High | 2017-01-03 | 2008-09-05 | View | |
5109 | CVE-2008-5331 | Adobe Acrobat 9 uses more efficient encryption than previous versions, which makes it easier for attackers to guess a document"s password via a brute-force attack. | 2 | 7.5 | High | 2017-01-03 | 2008-12-05 | View | |
70645 | CVE-2004-0189 | The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") character, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists. | 2 | 7.5 | High | 2016-12-20 | 2016-10-17 | View | |
70901 | CVE-2004-0465 | Directory traversal vulnerability in jretest.html in WebConnect 6.5 and 6.4.4, and possibly earlier versions, allows remote attackers to read keys within arbitrary INI formatted files via "..//" sequences in the WCP_USER parameter. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
5621 | CVE-2008-5890 | SQL injection vulnerability in feeds.php in Injader before 2.1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-04-04 | View |
Page 16934 of 17672, showing 5 records out of 88360 total, starting on record 84666, ending on 84670