NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
69594  CVE-2005-3956  Multiple SQL injection vulnerabilities in index.php in DMANews 0.904 and 0.910 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a comments action and the (2) sortorder and (3) display_num parameters in a news_list action.    7.5  High  2017-01-03  2008-10-03  View
73451  CVE-2003-0317  iisPROTECT 2.1 and 2.2 allows remote attackers to bypass authentication via an HTTP request containing URL-encoded characters.    7.5  High  2017-01-03  2008-10-03  View
4257  CVE-2008-4432  Cross-site scripting (XSS) vulnerability in search.php in the RMSOFT MiniShop module 1.0 for Xoops allows remote attackers to inject arbitrary web script or HTML via the itemsxpag parameter.    4.3  Medium  2017-01-03  2008-10-06  View
4129  CVE-2008-4301  ** DISPUTED ** A certain ActiveX control in iisext.dll in Microsoft Internet Information Services (IIS) allows remote attackers to set a password via a string argument to the SetPassword method. NOTE: this issue could not be reproduced by a reliable third party. In addition, the original researcher is unreliable. Therefore the original disclosure is probably erroneous.    10  High  2017-01-03  2008-10-07  View
4195  CVE-2008-4368  The default configuration of Java 1.5 on Apple Mac OS X 10.5.4 and 10.5.5 contains a jurisdiction policy that limits Java Cryptography Extension (JCE) key sizes to 128 bits, which makes it easier for attackers to decrypt ciphertext produced by JCE.    Medium  2017-01-03  2008-10-07  View

Page 2188 of 17672, showing 5 records out of 88360 total, starting on record 10936, ending on 10940

Actions