NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
69533  CVE-2005-3895  Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3, when AttachmentDownloadType is set to inline, renders text/html e-mail attachments as HTML in the browser when the queue moderator attempts to download the attachment, which allows remote attackers to execute arbitrary web script or HTML. NOTE: this particular issue is referred to as XSS by some sources.    5.8  Medium  2017-01-03  2016-10-17  View
4253  CVE-2008-4428  Unrestricted file upload vulnerability in upload.php in Phlatline"s Personal Information Manager (pPIM) 1.0 and earlier allows remote attackers to execute arbitrary code by uploading a .php file, then accessing it via a direct request to the file in the top-level directory.    10  High  2017-01-03  2009-01-29  View
69789  CVE-2005-4191  Multiple cross-site scripting (XSS) vulnerabilities in templates/tasklists/tasklists.inc in Horde Nag Task List Manager H3 before 2.0.4 allow remote authenticated users to inject arbitrary web script or HTML via (1) the tasklist"s name or (2) description, when creating a new tasklist.    3.5  Low  2017-01-03  2011-03-07  View
4509  CVE-2008-4695  Opera before 9.60 allows remote attackers to obtain sensitive information and have unspecified other impact by predicting the cache pathname of a cached Java applet and then launching this applet from the cache, leading to applet execution within the local-machine context.    9.3  High  2017-01-03  2011-03-07  View
70045  CVE-2005-4447  SQL injection vulnerability in articlesarticles_funcs.php in phpCOIN 1.2.2 allows remote attackers to modify SQL syntax and possibly execute SQL in limited circumstances via the rec_next parameter. NOTE: the original disclosure suggests that command injection is not feasible because the injection occurs after an "ORDER BY" clause, but it is likely that this bug could result in an error message path disclosure due to a syntax error, in some environments. Therefore this is an exposure and should be included in CVE.    7.5  High  2017-01-03  2008-09-05  View

Page 2941 of 17672, showing 5 records out of 88360 total, starting on record 14701, ending on 14705

Actions