NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
71455 | CVE-2004-1063 | PHP 4.x to 4.3.9, and PHP 5.x to 5.0.2, when running in safe mode on a multithreaded Unix webserver, allows local users to bypass safe_mode_exec_dir restrictions and execute commands outside of the intended safe_mode_exec_dir via shell metacharacters in the current directory name. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View | |
71711 | CVE-2004-1331 | The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the "File Download - Security Warning" dialog and save arbitrary files with arbitrary extensions via the SaveAs command. | 2 | 2.6 | Low | 2017-07-18 | 2017-07-10 | View | |
71967 | CVE-2004-1588 | SQL injection vulnerability in GoSmart Message Board allows remote attackers to execute arbitrary SQL code via the (1) QuestionNumber and Category parameters to Forum.asp or (2) Username and Password parameter to Login_Exec.asp. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
72223 | CVE-2004-1845 | Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to comment_add.asp, (2) search parameter to search.asp, or (3) n parameter to category_news_headline.asp. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
72479 | CVE-2004-2102 | Cross-site scripting (XSS) vulnerability in FREESCO 2.05, a modified version of thttpd, allows remote attackers to inject arbitrary web script or HTML via the test parameter. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 183 of 17672, showing 5 records out of 88360 total, starting on record 911, ending on 915