NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
68662  CVE-2005-2998  PHP Advanced Transfer Manager 1.30 has a default password for the administrator user, which allows remote attackers to upload and execute arbitrary PHP files.    7.5  High  2017-01-03  2008-09-05  View
3382  CVE-2008-3509  LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, which allows remote attackers to change the configuration or execute arbitrary PHP code via addition of blocks, and other vectors.    7.5  High  2017-01-03  2008-11-19  View
69430  CVE-2005-3792  Multiple SQL injection vulnerabilities in the Search module in PHP-Nuke 7.8, and possibly other versions before 7.9 with patch 3.1, allows remote attackers to execute arbitrary SQL commands, as demonstrated via the query parameter in a stories type.    7.5  High  2017-07-18  2017-07-10  View
69686  CVE-2005-4048  Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) in FFmpeg libavcodec 0.4.9-pre1 and earlier, as used in products such as (1) mplayer, (2) xine-lib, (3) Xmovie, and (4) GStreamer, allows remote attackers to execute arbitrary commands via small PNG images with palettes.    7.5  High  2017-01-03  2011-10-17  View
4406  CVE-2008-4590  Multiple SQL injection vulnerabilities in Stash 1.0.3 allow remote attackers to execute arbitrary SQL commands via (1) the username parameter to admin/login.php and (2) the post parameter to admin/news.php.    7.5  High  2017-01-03  2009-01-29  View

Page 2545 of 17672, showing 5 records out of 88360 total, starting on record 12721, ending on 12725

Actions