NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
2566 | CVE-2008-2668 | Multiple cross-site scripting (XSS) vulnerabilities in yBlog 0.2.2.2 allow remote attackers to inject arbitrary web script or HTML via (1) the q parameter to search.php, or the n parameter to (2) user.php or (3) uss.php. | 2 | 4.3 | Medium | 2017-01-03 | 2009-01-29 | View | |
68102 | CVE-2005-2411 | Cross-Site Request Forgery (CSRF) vulnerability in tDiary 2.1.1, and tDiary 2.0.1 and earlier, allows remote attackers to conduct actions as another user, and execute commands on the server, via a URL that is activated by the user. | 2 | 5.1 | Medium | 2017-07-18 | 2017-07-10 | View | |
3078 | CVE-2008-3195 | Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide is skipped, allows remote attackers to read arbitrary files via a query string containing a .. (dot dot) in the image variable, and execute arbitrary files via unspecified vectors. | 2 | 6.8 | Medium | 2017-01-03 | 2011-03-07 | View | |
68614 | CVE-2005-2950 | Cross-site scripting (XSS) vulnerability in Sawmill 7.0.0 through 7.1.13 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP GET request. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
68870 | CVE-2005-3208 | Multiple SQL injection vulnerabilities in (1) aeNovo, (2) aeNovoShop and (3) aeNovoWYSI allow remote attackers to execute arbitrary SQL code via (a) the password parameter in control.asp, and (b) the strSQL parameter in search.asp, which can enable XSS attacks in resulting error messages. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 224 of 17672, showing 5 records out of 88360 total, starting on record 1116, ending on 1120