NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
66242 | CVE-2005-0485 | Cross-site scripting (XSS) vulnerability in comment.php for paNews 2.0b4 for PHP Arena allows remote attackers to inject arbitrary HTML and web script via the showpost parameter. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
66498 | CVE-2005-0748 | PHP remote file inclusion vulnerability in initdb.php for WEBInsta Mailing list manager 1.3d allows remote attackers to execute arbitrary PHP code by modifying the absolute_path parameter to reference a URL on a remote web server that contains the code. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
66754 | CVE-2005-1005 | ProfitCode PayProCart 3.0 allows remote attackers to bypass authentication and gain administrative privileges to the admin control panel, as demonstrated via a direct request to adminshop/index.php with hex-encoded .. sequences in the ftoedit parameter. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
67266 | CVE-2005-1528 | Untrusted search path vulnerability in the crttrap command in QNX Neutrino RTOS 6.2.1 allows local users to load arbitrary libraries via a LD_LIBRARY_PATH environment variable that references a malicious library. | 2 | 7.2 | High | 2017-07-18 | 2017-07-10 | View | |
67778 | CVE-2005-2069 | pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 16971 of 17672, showing 5 records out of 88360 total, starting on record 84851, ending on 84855