NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 69048 | CVE-2005-3386 | SQL injection vulnerability in Techno Dreams Web Directory script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp. | 2 | 7.5 | High | 2017-01-03 | 2016-10-17 | View | |
| 69049 | CVE-2005-3387 | The startup script in packages/RedHat/ntop.init in ntop before 3.2, when ntop.conf is writable by users besides root, creates temporary files insecurely, which allows remote attackers to execute arbitrary code. | 2 | 4.6 | Medium | 2017-01-03 | 2011-03-07 | View | |
| 69050 | CVE-2005-3388 | Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a "stacked array assignment." | 2 | 4.3 | Medium | 2017-01-03 | 2016-12-07 | View | |
| 69051 | CVE-2005-3389 | The parse_str function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when called with only one parameter, allows remote attackers to enable the register_globals directive via inputs that cause a request to be terminated due to the memory_limit setting, which causes PHP to set an internal flag that enables register_globals and allows attackers to exploit vulnerabilities in PHP applications that would otherwise be protected. | 2 | 5 | Medium | 2017-01-03 | 2016-12-07 | View | |
| 69052 | CVE-2005-3390 | The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to modify the GLOBALS array and bypass security protections of PHP applications via a multipart/form-data POST request with a "GLOBALS" fileupload field. | 2 | 7.5 | High | 2017-01-03 | 2016-12-07 | View |
Page 2834 of 17672, showing 5 records out of 88360 total, starting on record 14166, ending on 14170