NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
69372  CVE-2005-3734  Cross-site scripting (XSS) vulnerability in the "add content" page in phpMyFAQ 1.5.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) thema, (2) username, and (3) usermail parameters.    4.3  Medium  2017-01-03  2011-03-07  View
4092  CVE-2008-4242  ProFTPD 1.3.1 interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execute arbitrary FTP commands via a long ftp:// URI that leverages an existing session from the FTP client implementation in a web browser.    6.8  Medium  2017-01-03  2009-03-06  View
4348  CVE-2008-4525  SQL injection vulnerability in index.php in AmpJuke 0.7.5 allows remote attackers to execute arbitrary SQL commands via the special parameter in a performerid action.    7.5  High  2017-01-03  2008-12-20  View
69884  CVE-2005-4286  Unspecified vulnerability in PhpLogCon before 1.2.2 allows remote attackers to use arbitrary profiles via unknown vectors involving ""smart" values for userid and password," probably involving an SQL injection vulnerability in the (1) pass and (2) usr parameters in submit.php.    7.5  High  2017-01-03  2011-03-07  View
4604  CVE-2008-4790  The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restrictions and read "files attached to content" via unknown vectors.    Medium  2017-01-03  2009-02-05  View

Page 17439 of 17672, showing 5 records out of 88360 total, starting on record 87191, ending on 87195

Actions