NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
68468  CVE-2005-2781  The Avatar upload feature in FUD Forum before 2.7.0 does not properly verify uploaded files, which allows remote attackers to execute arbitrary PHP code via a file with a .php extension that contains image data followed by PHP code.    7.5  High  2017-07-18  2017-07-10  View
68469  CVE-2005-2782  PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an "ftp://" URL in the alpath parameter, which bypasses the incomplete blacklist that only checks for "http" and "https" URLs.    7.5  High  2017-07-18  2017-07-10  View
68470  CVE-2005-2783  Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML via nested, malformed URL BBCode tags.    4.3  Medium  2017-07-18  2017-07-10  View
68471  CVE-2005-2784  SQL injection vulnerability in the login function for the administration login panel in cosmoshop 8.10.78 allows remote attackers to execute arbitrary SQL commands and bypass authentication via unspecified vectors.    7.5  High  2017-07-18  2017-07-10  View
68472  CVE-2005-2785  cosmoshop 8.10.78 and earlier stores passwords in plaintext in the database, which allows local users to obtain sensitive information.    2.1  Low  2017-07-18  2017-07-10  View

Page 2718 of 17672, showing 5 records out of 88360 total, starting on record 13586, ending on 13590

Actions