NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
30722 | CVE-2014-2268 | views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-install the application via a request that sets the X-Requested-With HTTP header, as demonstrated by executing arbitrary PHP code via the db_name parameter. | 2 | 5 | Medium | 2017-01-19 | 2014-11-18 | View | |
66108 | CVE-2005-0345 | viewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote attackers to view protected forums via the thread_id parameter. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
66355 | CVE-2005-0603 | viewtopic.php in phpBB 2.0.12 and earlier allows remote attackers to obtain sensitive information via a highlight parameter containing invalid regular expression syntax, which reveals the path in a PHP error message. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View | |
71695 | CVE-2004-1315 | viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special characters are inserted into the result, which is then processed by PHP exec, as exploited by the Santy.A worm. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
64043 | CVE-2006-5442 | ViewVC 1.0.2 and earlier does not specify a charset in its HTTP headers or HTML documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks that inject arbitrary UTF-7 encoded JavaScript code via a view. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 17049 of 17672, showing 5 records out of 88360 total, starting on record 85241, ending on 85245