NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 72396 | CVE-2004-2019 | The WebLinks module in Php-Nuke 6.x through 7.3 allows remote attackers to obtain sensitive information via an invalid show parameter, which displays the full path in a PHP error message. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72397 | CVE-2004-2020 | Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 6.x through 7.3 allow remote attackers inject arbitrary HTML or web script into the (1) optionbox parameter in the News module, (2) date parameter in the Statistics module, (3) year, month, and month_1 parameters in the Stories_Archive module, (4) mode, order, and thold parameters in the Surveys module, or (5) a SQL statement to index.php, as processed by mainfile.php. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72398 | CVE-2004-2021 | Directory traversal vulnerability in file_manager.php in osCommerce 2.2 allows remote attackers to view arbitrary files via a .. (dot dot) in the filename argument. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72399 | CVE-2004-2022 | ActivePerl 5.8.x and others, and Larry Wall's Perl 5.6.1 and others, when running on Windows systems, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the system command, which leads to a stack-based buffer overflow. NOTE: it is unclear whether this bug is in Perl or the OS API that is used by Perl. | 2 | 2.1 | Low | 2017-07-18 | 2017-07-10 | View | |
| 72400 | CVE-2004-2023 | SQL injection vulnerability in login.php in Zen Cart 1.1.2d, 1.1.4 before patch 1, and possibly other versions allows remote attackers to execute arbitrary SQL via the (1) admin_name or (2) admin_pass parameters. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 2032 of 17672, showing 5 records out of 88360 total, starting on record 10156, ending on 10160