NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 68253 | CVE-2005-2564 | Direct static code injection vulnerability in editcss.php in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary PHP code, HTML, and script via the csscontent parameter, which is directly inserted into the gbxfinal.css file. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
| 68254 | CVE-2005-2565 | Gravity Board X (GBX) 1.1 allows remote attackers to obtain sensitive information via (1) a 1 in the perm parameter to deletethread.php or a direct request to (2) ban.php, (3) addnews.php, (4) banned.php, (5) boardstats.php, (6) adminform.php, (7) /forms/admininfo.php, (8) /forms/announcements.php, (9) forms/banform.php, or (10) other pages in the /forms directory, which reveal the path in an error message. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 68255 | CVE-2005-2566 | Multiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) allow remote attackers to execute arbitrary SQL commands via the (1) FID parameter to board.php or (2) UID parameter to member.php. | 2 | 7.5 | High | 2017-01-03 | 2016-10-17 | View | |
| 68256 | CVE-2005-2567 | PHP remote file inclusion vulnerability in SysCP 1.2.10 and earlier allows remote attackers to execute arbitrary PHP code via the language parameter. | 2 | 7.5 | High | 2017-01-03 | 2016-10-17 | View | |
| 68257 | CVE-2005-2568 | Eval injection vulnerability in the template engine for SysCP 1.2.10 and earlier allows remote attackers to execute arbitrary PHP code via a string containing the code within "{" and "}" (curly bracket) characters, which are processed by the PHP eval function. | 2 | 7.5 | High | 2017-01-03 | 2016-10-17 | View |
Page 2675 of 17672, showing 5 records out of 88360 total, starting on record 13371, ending on 13375