NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
69743  CVE-2005-4135  Direct static code injection vulnerability in includes/newtopic.php in SimpleBBS 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the Host header (possibly the name parameter or variable), which is then written to data/topics.php.    7.5  High  2017-01-03  2011-03-07  View
4463  CVE-2008-4649  Session fixation vulnerability in Elxis CMS 2008.1 revision 2204 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.    7.5  High  2017-01-03  2009-07-22  View
69999  CVE-2005-4401  Cross-site scripting (XSS) vulnerability in Lutece 1.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the query parameter.    4.3  Medium  2017-01-03  2008-09-20  View
4719  CVE-2008-4930  MyBB (aka MyBulletinBoard) 1.4.2 does not properly handle an uploaded file with a nonstandard file type that contains HTML sequences, which allows remote attackers to cause that file to be processed as HTML by Internet Explorer"s content inspection, aka "Incomplete protection against MIME-sniffing." NOTE: this could be leveraged for XSS and other attacks.    Medium  2017-01-03  2008-11-05  View
70255  CVE-2005-4666  Cross-site scripting (XSS) vulnerability in PHlyMail before 3.3 Beta1 allows remote attackers to inject arbitrary Javascript via unknown attack vectors.    4.3  Medium  2017-01-03  2011-03-07  View

Page 2529 of 17672, showing 5 records out of 88360 total, starting on record 12641, ending on 12645

Actions