NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 4486 | CVE-2008-4672 | Cross-site scripting (XSS) vulnerability in search_results.php in buymyscripts Lyrics Script allows remote attackers to inject arbitrary web script or HTML via the k parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 4.3 | Medium | 2017-01-03 | 2008-10-22 | View | |
| 70022 | CVE-2005-4424 | Directory traversal vulnerability in PHPKIT 1.6.1 R2 and earlier might allow remote authenticated users to execute arbitrary PHP code via a .. (dot dot) in the path parameter and a %00 at the end of the filename, as demonstrated by an avatar filename ending with .png%00. | 2 | 6.5 | Medium | 2017-01-03 | 2008-09-05 | View | |
| 4742 | CVE-2008-4953 | ** DISPUTED ** firehol in firehol 1.256 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/.firehol-tmp-#####-*-* and (2) /tmp/firehol.conf temporary files. NOTE: the vendor disputes this vulnerability, stating that an attack "would require an attacker to create 1073741824*PID-RANGE symlinks." | 2 | 6.9 | Medium | 2017-01-03 | 2009-07-20 | View | |
| 70278 | CVE-2005-4689 | Six Apart Movable Type 3.16 stores account names and password hashes in a cookie, which allows remote attackers to login to an account by sniffing the cookie. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
| 4998 | CVE-2008-5214 | Cross-site scripting (XSS) vulnerability in service/calendrier.php in ClanLite 2.2006.05.20 allows remote attackers to inject arbitrary web script or HTML via the annee parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2009-01-29 | View |
Page 2737 of 17672, showing 5 records out of 88360 total, starting on record 13681, ending on 13685