NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
16166 | CVE-2010-4931 | ** DISPUTED ** Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the folder_level parameter. NOTE: this issue has been disputed by a reliable third party. | 2 | 10 | High | 2017-01-18 | 2012-05-14 | View | |
6609 | CVE-2008-6878 | ** DISPUTED ** Directory traversal vulnerability in admin/includes/languages/english.php in Zen Cart 1.3.8a, 1.3.8, and earlier, when .htaccess is not supported, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the _SESSION[language] parameter. NOTE: the vendor disputes this issue, stating "at worst, the use of this vulnerability will reveal some local file paths." | 2 | 6.8 | Medium | 2017-01-03 | 2009-07-28 | View | |
59464 | CVE-2006-0733 | ** DISPUTED ** Cross-site scripting (XSS) vulnerability in WordPress 2.0.0 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes such as (1) onfocus and (2) onblur in the "author"s website" field. NOTE: followup comments to the researcher"s web log suggest that this issue is only exploitable by the same user who injects the XSS, so this might not be a vulnerability. | 2 | 2.6 | Low | 2016-12-20 | 2008-09-05 | View | |
33908 | CVE-2014-6392 | ** DISPUTED ** Cross-site scripting (XSS) vulnerability in the Facebook app 14.0 and the Facebook Messenger app 10.0 for iOS allows remote attackers to inject arbitrary web script or HTML via a crafted filename extension that is improperly handled during MIME sniffing of chat traffic. NOTE: the vendor disputes the significance of this report, because the user must accept an interstitial warning before the HTML file content is rendered, and because the HTML content"s origin is a sandbox domain. | 2 | 4.3 | Medium | 2017-01-19 | 2014-09-23 | View | |
30223 | CVE-2014-1607 | ** DISPUTED ** Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject arbitrary web script or HTML via the year parameter to eventcalander/. NOTE: this issue has been disputed by the Drupal Security Team; it may be site-specific. If so, then this CVE will be REJECTed in the future. | 2 | 4.3 | Medium | 2017-01-19 | 2014-10-18 | View |
Page 17599 of 17672, showing 5 records out of 88360 total, starting on record 87991, ending on 87995