NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 1866 | CVE-2008-1930 | The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as demonstrated by registering usernames beginning with "admin" to obtain administrator privileges, aka a "cryptographic splicing" issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-6013. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
| 67402 | CVE-2005-1677 | Unknown vulnerability in Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 allows remote attackers to bypass restrictions on COM objects. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
| 67658 | CVE-2005-1943 | Multiple SQL injection vulnerabilities in Loki download manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) password field to default.asp or (2) cat parameter to catinfo.asp. | 2 | 7.5 | High | 2017-01-03 | 2016-10-17 | View | |
| 70218 | CVE-2005-4629 | SQL injection vulnerability in SMBCMS 2.1 allows remote attackers to execute arbitrary SQL commands via unspecified search parameters. | 2 | 7.5 | High | 2017-01-03 | 2008-09-20 | View | |
| 70474 | CVE-2005-4885 | Unspecified vulnerability on certain Sun StorEdge 6130 (SE6130) Controller Arrays allows remote attackers to delete data via unknown vectors. | 2 | 7.5 | High | 2017-01-03 | 2010-01-31 | View |
Page 2768 of 17672, showing 5 records out of 88360 total, starting on record 13836, ending on 13840