NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
2051  CVE-2008-2117  Cross-site scripting (XSS) vulnerability in pages/news.page.inc in Project Alumni 1.0.9 allows remote attackers to inject arbitrary web script or HTML via the year parameter in a news action to index.php, a different vector than CVE-2007-6126.    4.3  Medium  2017-01-03  2009-01-29  View
67587  CVE-2005-1869  PHP remote file inclusion vulnerability in start_lobby.php in MWChat 6.x allows remote attackers to execute arbitrary PHP code via the CONFIG[MWCHAT_Libs] parameter.    7.5  High  2017-01-03  2008-09-05  View
2307  CVE-2008-2391  SubSonic allows remote attackers to bypass pagesize limits and cause a denial of service (CPU consumption) via a pageindex (aka data page number) of -1.    7.8  High  2017-01-03  2009-01-29  View
67843  CVE-2005-2139  PHP remote file inclusion vulnerability in user_check.php for Pavsta Auto Site allows remote attackers to execute arbitrary PHP code via the sitepath parameter.    Medium  2017-01-03  2011-03-07  View
2563  CVE-2008-2665  Directory traversal vulnerability in the posix_access function in PHP 5.2.6 and earlier allows remote attackers to bypass safe_mode restrictions via a .. (dot dot) in an http URL, which results in the URL being canonicalized to a local filename after the safe_mode check has successfully run.    Medium  2017-01-03  2012-10-30  View

Page 184 of 17672, showing 5 records out of 88360 total, starting on record 916, ending on 920

Actions