NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 72416 | CVE-2004-2039 | e107 0.615 allows remote attackers to obtain sensitive information via a direct request to (1) alt_news.php, (2) backend_menu.php, (3) clock_menu.php, (4) counter_menu.php, (5) login_menu.php, and other files, which reveal the full path in a PHP error message. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72417 | CVE-2004-2040 | Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary web script or HTML via the (1) LAN_407 parameter to clock_menu.php, (2) "email article to a friend" field, (3) "submit news" field, or (4) avmsg parameter to usersettings.php. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72418 | CVE-2004-2041 | PHP remote file inclusion vulnerability in secure_img_render.php in e107 0.615 allows remote attackers to execute arbitrary PHP code by modifying the p parameter to reference a URL on a remote web server that contains the code. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
| 72419 | CVE-2004-2042 | Multiple SQL injection vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary SQL code and gain sensitive information via (1) content parameter to content.php, (2) content_id parameter to content.php, or (3) list parameter to news.php. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
| 72420 | CVE-2004-2043 | Buffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows remote attackers to cause a denial of service (crash) via a long database name, as demonstrated using the gsec command. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 2036 of 17672, showing 5 records out of 88360 total, starting on record 10176, ending on 10180