NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
70389  CVE-2005-4800  Direct static code injection vulnerability in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allows remote authenticated administrators to inject arbitrary PHP code via the TestGallery parameter in a mod_info action to modify_gallery.php, which inserts the code into guid_info.php. NOTE: this issue is easier to exploit due to a separate CSRF vulnerability.    High  2017-01-03  2008-09-05  View
5109  CVE-2008-5331  Adobe Acrobat 9 uses more efficient encryption than previous versions, which makes it easier for attackers to guess a document"s password via a brute-force attack.    7.5  High  2017-01-03  2008-12-05  View
70645  CVE-2004-0189  The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") character, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.    7.5  High  2016-12-20  2016-10-17  View
70901  CVE-2004-0465  Directory traversal vulnerability in jretest.html in WebConnect 6.5 and 6.4.4, and possibly earlier versions, allows remote attackers to read keys within arbitrary INI formatted files via "..//" sequences in the WCP_USER parameter.    Medium  2017-07-18  2017-07-10  View
5621  CVE-2008-5890  SQL injection vulnerability in feeds.php in Injader before 2.1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.    7.5  High  2017-01-03  2009-04-04  View

Page 16934 of 17672, showing 5 records out of 88360 total, starting on record 84666, ending on 84670

Actions