NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 69028 | CVE-2005-3366 | PHP file inclusion vulnerability in index.php in PHP iCalendar 2.0a2 through 2.0.1 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the phpicalendar cookie. NOTE: this is not a cross-site scripting (XSS) issue as claimed by the original researcher. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 69029 | CVE-2005-3367 | Cross-site scripting (XSS) vulnerability in journal.php in SparkleBlog 2.1 allows remote attackers to inject arbitrary web script or HTML via the name field. | 2 | 4.3 | Medium | 2017-01-03 | 2016-10-17 | View | |
| 69030 | CVE-2005-3368 | Cross-site scripting (XSS) vulnerability in the Search_Enhanced module in PHP-Nuke 7.9 allows remote attackers to inject arbitrary web script or HTML via the query parameter. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 69031 | CVE-2005-3369 | Multiple SQL injection vulnerabilities in the Info-DB module (info_db.php) in Woltlab Burning Board 2.7 and earlier allow remote attackers to execute arbitrary SQL commands and possibly upload files via the (1) fileid and (2) subkatid parameters. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
| 69032 | CVE-2005-3370 | Multiple interpretation error in ArcaVir 2005 package 2005-06-21 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by applications on the end system, as demonstrated by a "triple headed" program that contains EXE, EML, and HTML content, aka the "magic byte bug." | 2 | 5.1 | Medium | 2017-01-03 | 2016-10-17 | View |
Page 2830 of 17672, showing 5 records out of 88360 total, starting on record 14146, ending on 14150