NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
68228  CVE-2005-2539  Multiple cross-site scripting (XSS) vulnerabilities in FlatNuke 2.5.5 and possibly earlier versions allow remote attackers to inject arbitrary web script or HTML via the (1) bodycolor, (2) backimage, (3) theme, or (4) logo parameter to structure.php, (5) admin, (6) admin_mail, or (7) back parameter to footer.php, or (8) the message body in a news post.    4.3  Medium  2017-07-18  2017-07-10  View
68229  CVE-2005-2540  CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII char 13 (carriage return) in the signature field, which is injected into a PHP script without a preceding comment character, which can then be executed by a direct request.    Medium  2017-07-18  2017-07-10  View
68230  CVE-2005-2541  Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.    10  High  2017-01-03  2016-10-17  View
68231  CVE-2005-2542  Invision Power Board (IPB) 1.0.3 allows remote attackers to inject arbitrary web script or HTML via an attachment, which is automatically downloaded and processed as HTML.    Medium  2017-01-03  2016-10-17  View
68232  CVE-2005-2543  Directory traversal vulnerability in wce.download.php in Comdev eCommerce 3.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the download parameter.    Medium  2017-01-03  2016-10-17  View

Page 2670 of 17672, showing 5 records out of 88360 total, starting on record 13346, ending on 13350

Actions