NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
66776 | CVE-2005-1027 | Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x through 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter in the Your_Account module, (2) avatarcategory parameter in the Your_Account module, or (3) lid parameter in the Downloads module. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
67288 | CVE-2005-1561 | Multiple cross-site scripting (XSS) vulnerabilities in post.asp in MaxWebPortal 1.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mod, (2) M, or (3) type parameter. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
67800 | CVE-2005-2091 | IBM WebSphere 5.1 and WebSphere 5.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebSphere to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling." | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
68568 | CVE-2005-2893 | Direct static code injection vulnerability in setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via the username (u parameter), which is directly injected into a file that is later executed upon login. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
70872 | CVE-2004-0425 | Heap-based buffer overflow in SiteMinder Affiliate Agent 4.x allows remote attackers to execute arbitrary code via a large SMPROFILE cookie. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View |
Page 17458 of 17672, showing 5 records out of 88360 total, starting on record 87286, ending on 87290