NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 72436 | CVE-2004-2059 | Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers inject arbitrary web script or HTML via the (1) SearchFor parameter in [TABLE-NAME]_search.asp, (2) SQL parameter in [TABLE-NAME]_edit.asp, (3) SearchFor parameter in [TABLE]_list.asp, or (4) SQL parameter in export.asp. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72437 | CVE-2004-2060 | ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72438 | CVE-2004-2061 | RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
| 72439 | CVE-2004-2062 | SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary SQL via the (1) thread_id, (2) parent_id, or (3) mode parameters. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
| 72440 | CVE-2004-2063 | Cross-site scripting (XSS) vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to inject arbitrary HTML or web script via the feedback parameter. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 2040 of 17672, showing 5 records out of 88360 total, starting on record 10196, ending on 10200