NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 70699 | CVE-2004-0248 | Cross-site scripting vulnerability (XSS) in PHPX 3.2.3 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into (1) keywords argument of main.inc.php, (2) body argument of help.inc.php, or (3) the subject field in Personal Messages and Forum. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 5419 | CVE-2008-5677 | Unrestricted file upload vulnerability in Kwalbum 2.0.4, 2.0.2, and earlier, when PICS_PATH is located in the web root, allows remote authenticated users with upload capability to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file under items/, related to the ReplaceBadFilenameChars function in include/ItemAdder.php. NOTE: some of these details are obtained from third party information. | 2 | 7.1 | High | 2017-01-03 | 2009-01-29 | View | |
| 70955 | CVE-2004-0521 | SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown impact, probably via abook_database.php. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View | |
| 5675 | CVE-2008-5944 | Cross-site scripting (XSS) vulnerability in modules.php in NavBoard 16 (2.6.0) allows remote attackers to inject arbitrary web script or HTML via the module parameter. | 2 | 2.6 | Low | 2017-01-03 | 2009-03-18 | View | |
| 71211 | CVE-2004-0787 | Cross-site scripting (XSS) vulnerability in the web frontend in OpenCA 0.9.1-8 and earlier, and 0.9.2 RC6 and earlier, allows remote attackers to inject arbitrary web script or HTML via the form input fields. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 2927 of 17672, showing 5 records out of 88360 total, starting on record 14631, ending on 14635