NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5620 | CVE-2008-5889 | Cross-site scripting (XSS) vulnerability in user.asp in Click&Rank allows remote attackers to inject arbitrary web script or HTML via the action parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2009-01-12 | View | |
71156 | CVE-2004-0729 | PhpBB 2.0.8 allows remote attackers to gain sensitive information via an invalid (1) category_rows parameter to index.php, (2) faq parameter to faq.php, or (3) ranksrow parameter to profile.php, which reveal the full path in an error message. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
6388 | CVE-2008-6657 | Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote attackers to hijack the authentication of admins for requests that install packages via the package parameter in an install2 action. | 2 | 6.8 | Medium | 2017-01-03 | 2009-07-23 | View | |
71924 | CVE-2004-1545 | UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
6644 | CVE-2008-6913 | Unrestricted file upload vulnerability in editresume_next.php in Zeeways ZEEJOBSITE 2.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a photo in a profile edit action, then accessing the file via a direct request to jobseekers/logos/. | 2 | 6.5 | Medium | 2017-01-03 | 2009-08-13 | View |
Page 17246 of 17672, showing 5 records out of 88360 total, starting on record 86226, ending on 86230