NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
70751 | CVE-2004-0300 | SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View | |
70752 | CVE-2004-0301 | Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
70753 | CVE-2004-0302 | Directory traversal vulnerability in OWLS 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter in index.php, (2) editfile in glossary.php, or (3) editfile in newmultiplechoice.php. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
70754 | CVE-2004-0303 | OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
70755 | CVE-2004-0304 | SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View |
Page 1703 of 17672, showing 5 records out of 88360 total, starting on record 8511, ending on 8515