NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
70048 | CVE-2005-4450 | Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.7.0 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag to server_privileges.php, as demonstrated using the dbname and checkprivs parameters. NOTE: the provenance of this issue is unknown, although third parties imply that it is related to the disclosure of CVE-2005-4349, which was labeled as SQL injection but disputed. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
70304 | CVE-2005-4715 | Multiple SQL injection vulnerabilities in modules.php in PHP-Nuke 7.8, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) sid, and (3) pid parameters in a POST request, which bypasses security checks that are performed for GET requests. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
71328 | CVE-2004-0926 | Heap-based buffer overflow in Apple QuickTime on Mac OS 10.2.8 through 10.3.5 may allow remote attackers to execute arbitrary code via a certain BMP image. | 2 | 10 | High | 2016-12-20 | 2008-09-05 | View | |
73120 | CVE-2004-2743 | upload.cgi in Mega Upload Progress Bar before 1.45 allows remote attackers to copy or overwrite arbitrary files via unspecified parameters related to names of uploaded files. | 2 | 6.4 | Medium | 2016-12-20 | 2008-09-05 | View | |
74400 | CVE-2003-1330 | Clearswift MAILsweeper for SMTP 4.3.6 SP1 does not execute custom "on strip unsuccessful" hooks, which allows remote attackers to bypass e-mail attachment filtering policies via an attachment that MAILsweeper can detect but not remove. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 17047 of 17672, showing 5 records out of 88360 total, starting on record 85231, ending on 85235