NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 68228 | CVE-2005-2539 | Multiple cross-site scripting (XSS) vulnerabilities in FlatNuke 2.5.5 and possibly earlier versions allow remote attackers to inject arbitrary web script or HTML via the (1) bodycolor, (2) backimage, (3) theme, or (4) logo parameter to structure.php, (5) admin, (6) admin_mail, or (7) back parameter to footer.php, or (8) the message body in a news post. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 68229 | CVE-2005-2540 | CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII char 13 (carriage return) in the signature field, which is injected into a PHP script without a preceding comment character, which can then be executed by a direct request. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 68230 | CVE-2005-2541 | Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges. | 2 | 10 | High | 2017-01-03 | 2016-10-17 | View | |
| 68231 | CVE-2005-2542 | Invision Power Board (IPB) 1.0.3 allows remote attackers to inject arbitrary web script or HTML via an attachment, which is automatically downloaded and processed as HTML. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View | |
| 68232 | CVE-2005-2543 | Directory traversal vulnerability in wce.download.php in Comdev eCommerce 3.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the download parameter. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View |
Page 2670 of 17672, showing 5 records out of 88360 total, starting on record 13346, ending on 13350