NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
69157 | CVE-2005-3496 | Cross-site scripting (XSS) vulnerability in PHP Handicapper allows remote attackers to inject arbitrary web script or HTML via the msg parameter to msg.php. NOTE: some sources identify a second vector in the login parameter to process_signup.php, but the original source says that it is for CRLF injection (CVE-2005-4712). Also note: the vendor has disputed CVE-2005-3497, and it is possible that the dispute was intended to include this issue as well. If so, followup investigation strongly suggests that the original report is correct. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View | |
3877 | CVE-2008-4015 | Unspecified vulnerability in the Oracle Streams component in Oracle Database 10.1.0.5 allows remote authenticated users to affect confidentiality and integrity, related to SYS.DBMS_STREAMS_AUTH. | 2 | 5.5 | Medium | 2017-01-03 | 2012-10-22 | View | |
69413 | CVE-2005-3775 | PHP remote file inclusion vulnerability in pollvote.php in PollVote allows remote attackers to include arbitrary files via a URL in the pollname parameter. | 2 | 7.5 | High | 2017-01-03 | 2016-10-17 | View | |
4133 | CVE-2008-4305 | Static code injection vulnerability in installation/setup.php in phpCollab 2.5 rc3 and earlier allows remote authenticated administrators to inject arbitrary PHP code into include/settings.php via the URI. | 2 | 9 | High | 2017-01-03 | 2008-12-23 | View | |
69669 | CVE-2005-4031 | Eval injection vulnerability in MediaWiki 1.5.x before 1.5.3 allows remote attackers to execute arbitrary PHP code via the "user language option," which is used as part of a dynamic class name that is processed using the eval function. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View |
Page 1845 of 17672, showing 5 records out of 88360 total, starting on record 9221, ending on 9225