NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
16166  CVE-2010-4931  ** DISPUTED ** Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the folder_level parameter. NOTE: this issue has been disputed by a reliable third party.    10  High  2017-01-18  2012-05-14  View
6609  CVE-2008-6878  ** DISPUTED ** Directory traversal vulnerability in admin/includes/languages/english.php in Zen Cart 1.3.8a, 1.3.8, and earlier, when .htaccess is not supported, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the _SESSION[language] parameter. NOTE: the vendor disputes this issue, stating "at worst, the use of this vulnerability will reveal some local file paths."    6.8  Medium  2017-01-03  2009-07-28  View
59464  CVE-2006-0733  ** DISPUTED ** Cross-site scripting (XSS) vulnerability in WordPress 2.0.0 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes such as (1) onfocus and (2) onblur in the "author"s website" field. NOTE: followup comments to the researcher"s web log suggest that this issue is only exploitable by the same user who injects the XSS, so this might not be a vulnerability.    2.6  Low  2016-12-20  2008-09-05  View
33908  CVE-2014-6392  ** DISPUTED ** Cross-site scripting (XSS) vulnerability in the Facebook app 14.0 and the Facebook Messenger app 10.0 for iOS allows remote attackers to inject arbitrary web script or HTML via a crafted filename extension that is improperly handled during MIME sniffing of chat traffic. NOTE: the vendor disputes the significance of this report, because the user must accept an interstitial warning before the HTML file content is rendered, and because the HTML content"s origin is a sandbox domain.    4.3  Medium  2017-01-19  2014-09-23  View
30223  CVE-2014-1607  ** DISPUTED ** Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject arbitrary web script or HTML via the year parameter to eventcalander/. NOTE: this issue has been disputed by the Drupal Security Team; it may be site-specific. If so, then this CVE will be REJECTed in the future.    4.3  Medium  2017-01-19  2014-10-18  View

Page 17599 of 17672, showing 5 records out of 88360 total, starting on record 87991, ending on 87995

Actions