NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
80797  CVE-2002-1846  Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password, which allows remote attackers to modify passwords by stealing the cookie of another user, modifying the expiretime setting, and submitting the change in a profile2 action to index.php.    Medium  2017-01-05  2008-09-05  View
81053  CVE-2002-2102  InfBlocks.java in JCraft JZlib before 0.0.7 allow remote attackers to cause a denial of service (NullPointerException) via an invalid block of deflated data.    Medium  2017-01-05  2008-09-05  View
81309  CVE-2002-2358  Cross-site scripting (XSS) vulnerability in the FTP view feature in Opera 6.0 and 6.01 through 6.04 allows remote attackers to inject arbitrary web script or HTML via the title tag of an FTP URL.    4.3  Medium  2017-01-05  2008-09-05  View
53661  CVE-2007-1477  ** DISPUTED ** Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cfg_language parameter. NOTE: this issue has been disputed by CVE, since the cfg_language variable is configured upon proper product installation.    7.5  High  2017-01-07  2008-09-05  View
55709  CVE-2007-3558  SQL injection vulnerability in Coppermine Photo Gallery (CPG) before 1.4.11 allows remote attackers to execute arbitrary SQL commands via an album password cookie to an unspecified component.    7.5  High  2017-01-07  2008-09-05  View

Page 17031 of 17672, showing 5 records out of 88360 total, starting on record 85151, ending on 85155

Actions