NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
69635  CVE-2005-3997  Zen Cart 1.2.6d and earlier, under certain PHP configurations, allows remote attackers to obtain sensitive information via direct requests to files in the admin/includes directory, including (1) graphs/banner_daily.php, (2) graphs/banner_infobox.php, (3) graphs/banner_yearly.php, (4) graphs/banner_monthly.php, (5) application_bottom.php, (6) attributes_preview.php, (7) modules/category_product_listing.php, (8) modules/copy_to_confirm.php, (9) modules/delete_product_confirm.php, and (10) modules/move_product_confirm.php, which leaks the web server path in the resulting error message.    2.6  Low  2017-01-03  2011-03-07  View
4355  CVE-2008-4532  Cross-site scripting (XSS) vulnerability in index.php in MaxiScript Website Directory allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a search action.    4.3  Medium  2017-01-03  2009-01-29  View
69891  CVE-2005-4293  Cross-site scripting (XSS) vulnerability in cp-app.cgi in ClickCartPro (CCP) 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the affl parameter.    4.3  Medium  2017-01-03  2011-03-07  View
4611  CVE-2008-4797  Directory traversal vulnerability in Arihiro Kurata Kantan WEB Server 1.8 and earlier allows remote attackers to read arbitrary files via unknown vectors.    Medium  2017-01-03  2008-11-18  View
70147  CVE-2005-4558  IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter to mail/settings.html before it is stored in a database, which can allow remote authenticated users to include arbitrary PHP code via a URL in a modified lang_settings parameter to mail/index.html.    6.5  Medium  2017-01-03  2016-10-17  View

Page 187 of 17672, showing 5 records out of 88360 total, starting on record 931, ending on 935

Actions