NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
68613  CVE-2005-2949  pam_per_user before 0.4 does not verify if the user name changes between authentication attempts and uses the same subrequest handle, which allows remote attackers or local users to login as other users by using certain applications that allow the username to be changed during authentication, such as /bin/login.    7.5  High  2017-01-03  2016-10-17  View
68614  CVE-2005-2950  Cross-site scripting (XSS) vulnerability in Sawmill 7.0.0 through 7.1.13 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP GET request.    4.3  Medium  2017-07-18  2017-07-10  View
68615  CVE-2005-2951  Directory traversal vulnerability in security.inc.php in AzDGDatingLite 2.1.3, and possibly earlier versions, allows remote attackers to execute arbitrary PHP commands via ".." sequences and "%00" (trailing null byte) characters in the l parameter, which is used in an include_once statement.    7.5  High  2017-07-18  2017-07-10  View
68616  CVE-2005-2952  Directory traversal vulnerability in s.pl in Subscribe Me Pro 2.044.09P and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the l parameter.    Medium  2017-07-18  2017-07-10  View
68617  CVE-2005-2953  Cross-site scripting (XSS) vulnerability in merchant.mvc in MIVA Merchant 5 allows remote attackers to inject arbitrary web script or HTML via the Customer_Login parameter.    4.3  Medium  2017-01-03  2016-10-17  View

Page 2747 of 17672, showing 5 records out of 88360 total, starting on record 13731, ending on 13735

Actions