NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
67918  CVE-2005-2216  PHP remote file inclusion vulnerability in gals.php in PhotoGal Photo Gallery 1.5 and earlier allows remote attackers to execute arbitrary code via the news_file parameter.    7.5  High  2017-01-03  2008-09-05  View
67919  CVE-2005-2217  Dansie Shopping Cart stores the vars.dat file under the web root with insufficient access control, which might allow remote attackers to obtain sensitive information such as program variables.    Medium  2017-01-03  2008-09-05  View
67920  CVE-2005-2218  The device file system (devfs) in FreeBSD 5.x does not properly check parameters of the node type when creating a device node, which makes hidden devices available to attackers, who can then bypass restrictions on a jailed process.    7.2  High  2017-07-18  2017-07-10  View
67921  CVE-2005-2219  Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying the credit limit, via a direct request to AccountActions.asp and modifying the CreditLimit parameter in an UpdateCreditLimit action.    4.6  Medium  2017-01-03  2008-09-05  View
67922  CVE-2005-2220  ** DISPUTED ** Dragonfly Commerce allows remote attackers to change a product price by modifying the x_DragonflyCartProductPrice hidden field to (1) dc_Categorieslist.asp, (2) dc_Categoriesview.asp, (3) dc_productslist.asp, and (4) dc_productslist_Clearance.asp. NOTE: the vendor has disputed this issue, saying that "Dragonfly Commerce does not allow for editing prices nor does it allow for viewing information about clients stored in the database except by the store owner and authorized staff as appointed in the store administration." However, SecurityTracker claims that they have been able to confirm the problem.    Medium  2017-01-03  2016-10-17  View

Page 2608 of 17672, showing 5 records out of 88360 total, starting on record 13036, ending on 13040

Actions