NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
5620  CVE-2008-5889  Cross-site scripting (XSS) vulnerability in user.asp in Click&Rank allows remote attackers to inject arbitrary web script or HTML via the action parameter.    4.3  Medium  2017-01-03  2009-01-12  View
71156  CVE-2004-0729  PhpBB 2.0.8 allows remote attackers to gain sensitive information via an invalid (1) category_rows parameter to index.php, (2) faq parameter to faq.php, or (3) ranksrow parameter to profile.php, which reveal the full path in an error message.    Medium  2017-07-18  2017-07-10  View
6388  CVE-2008-6657  Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote attackers to hijack the authentication of admins for requests that install packages via the package parameter in an install2 action.    6.8  Medium  2017-01-03  2009-07-23  View
71924  CVE-2004-1545  UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code.    Medium  2017-07-18  2017-07-10  View
6644  CVE-2008-6913  Unrestricted file upload vulnerability in editresume_next.php in Zeeways ZEEJOBSITE 2.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a photo in a profile edit action, then accessing the file via a direct request to jobseekers/logos/.    6.5  Medium  2017-01-03  2009-08-13  View

Page 17246 of 17672, showing 5 records out of 88360 total, starting on record 86226, ending on 86230

Actions