NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
4486  CVE-2008-4672  Cross-site scripting (XSS) vulnerability in search_results.php in buymyscripts Lyrics Script allows remote attackers to inject arbitrary web script or HTML via the k parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.    4.3  Medium  2017-01-03  2008-10-22  View
70022  CVE-2005-4424  Directory traversal vulnerability in PHPKIT 1.6.1 R2 and earlier might allow remote authenticated users to execute arbitrary PHP code via a .. (dot dot) in the path parameter and a %00 at the end of the filename, as demonstrated by an avatar filename ending with .png%00.    6.5  Medium  2017-01-03  2008-09-05  View
4742  CVE-2008-4953  ** DISPUTED ** firehol in firehol 1.256 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/.firehol-tmp-#####-*-* and (2) /tmp/firehol.conf temporary files. NOTE: the vendor disputes this vulnerability, stating that an attack "would require an attacker to create 1073741824*PID-RANGE symlinks."    6.9  Medium  2017-01-03  2009-07-20  View
70278  CVE-2005-4689  Six Apart Movable Type 3.16 stores account names and password hashes in a cookie, which allows remote attackers to login to an account by sniffing the cookie.    Medium  2017-01-03  2008-09-05  View
4998  CVE-2008-5214  Cross-site scripting (XSS) vulnerability in service/calendrier.php in ClanLite 2.2006.05.20 allows remote attackers to inject arbitrary web script or HTML via the annee parameter.    4.3  Medium  2017-01-03  2009-01-29  View

Page 2737 of 17672, showing 5 records out of 88360 total, starting on record 13681, ending on 13685

Actions