NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 66603 | CVE-2005-0853 | betaparticle blog (bp blog) stores the database under the web root, which allows remote attackers to obtain sensitive information via a direct request to (1) dbBlogMX.mdb for versions before 3.0, or (2) Blog.mdb for versions 3.0 and later. NOTE: it was later reported that vector 2 also affects versions 6.0 through 9.0. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 66604 | CVE-2005-0854 | betaparticle blog (bp blog), posisbly before version 4, allows remote attackers to bypass authentication and (1) upload files via a direct request to upload.asp or (2) delete files via a direct request to myFiles.asp. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
| 66605 | CVE-2005-0855 | CoolForum 0.8.1 beta and earlier allows remote attackers to obtain sensitive path information via direct requests to (1) entete.php, (2) profile_accueil.php, (3) profile_mdp.php, (4) profile_notify.php, (5) profile_options.php, (6) profile_perso.php, (7) profile_pm.php, or (8) readannonce.php, which leaks the full pathname in a PHP error message. | 2 | 10 | High | 2017-01-03 | 2008-09-05 | View | |
| 66606 | CVE-2005-0856 | CoolForum 0.8.1 beta and earlier allows remote attackers to manipulate SQL commands via certain requests to (1) alert.php or (2) viewip.php, possibly due to a SQL injection vulnerability. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
| 66607 | CVE-2005-0857 | Cross-site scripting (XSS) vulnerability in avatar.php for CoolForum 0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the img parameter. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 2345 of 17672, showing 5 records out of 88360 total, starting on record 11721, ending on 11725