NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
69157  CVE-2005-3496  Cross-site scripting (XSS) vulnerability in PHP Handicapper allows remote attackers to inject arbitrary web script or HTML via the msg parameter to msg.php. NOTE: some sources identify a second vector in the login parameter to process_signup.php, but the original source says that it is for CRLF injection (CVE-2005-4712). Also note: the vendor has disputed CVE-2005-3497, and it is possible that the dispute was intended to include this issue as well. If so, followup investigation strongly suggests that the original report is correct.    4.3  Medium  2017-01-03  2011-03-07  View
3877  CVE-2008-4015  Unspecified vulnerability in the Oracle Streams component in Oracle Database 10.1.0.5 allows remote authenticated users to affect confidentiality and integrity, related to SYS.DBMS_STREAMS_AUTH.    5.5  Medium  2017-01-03  2012-10-22  View
69413  CVE-2005-3775  PHP remote file inclusion vulnerability in pollvote.php in PollVote allows remote attackers to include arbitrary files via a URL in the pollname parameter.    7.5  High  2017-01-03  2016-10-17  View
4133  CVE-2008-4305  Static code injection vulnerability in installation/setup.php in phpCollab 2.5 rc3 and earlier allows remote authenticated administrators to inject arbitrary PHP code into include/settings.php via the URI.    High  2017-01-03  2008-12-23  View
69669  CVE-2005-4031  Eval injection vulnerability in MediaWiki 1.5.x before 1.5.3 allows remote attackers to execute arbitrary PHP code via the "user language option," which is used as part of a dynamic class name that is processed using the eval function.    7.5  High  2017-01-03  2011-03-07  View

Page 1845 of 17672, showing 5 records out of 88360 total, starting on record 9221, ending on 9225

Actions