NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 69533 | CVE-2005-3895 | Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3, when AttachmentDownloadType is set to inline, renders text/html e-mail attachments as HTML in the browser when the queue moderator attempts to download the attachment, which allows remote attackers to execute arbitrary web script or HTML. NOTE: this particular issue is referred to as XSS by some sources. | 2 | 5.8 | Medium | 2017-01-03 | 2016-10-17 | View | |
| 4253 | CVE-2008-4428 | Unrestricted file upload vulnerability in upload.php in Phlatline"s Personal Information Manager (pPIM) 1.0 and earlier allows remote attackers to execute arbitrary code by uploading a .php file, then accessing it via a direct request to the file in the top-level directory. | 2 | 10 | High | 2017-01-03 | 2009-01-29 | View | |
| 69789 | CVE-2005-4191 | Multiple cross-site scripting (XSS) vulnerabilities in templates/tasklists/tasklists.inc in Horde Nag Task List Manager H3 before 2.0.4 allow remote authenticated users to inject arbitrary web script or HTML via (1) the tasklist"s name or (2) description, when creating a new tasklist. | 2 | 3.5 | Low | 2017-01-03 | 2011-03-07 | View | |
| 4509 | CVE-2008-4695 | Opera before 9.60 allows remote attackers to obtain sensitive information and have unspecified other impact by predicting the cache pathname of a cached Java applet and then launching this applet from the cache, leading to applet execution within the local-machine context. | 2 | 9.3 | High | 2017-01-03 | 2011-03-07 | View | |
| 70045 | CVE-2005-4447 | SQL injection vulnerability in articlesarticles_funcs.php in phpCOIN 1.2.2 allows remote attackers to modify SQL syntax and possibly execute SQL in limited circumstances via the rec_next parameter. NOTE: the original disclosure suggests that command injection is not feasible because the injection occurs after an "ORDER BY" clause, but it is likely that this bug could result in an error message path disclosure due to a syntax error, in some environments. Therefore this is an exposure and should be included in CVE. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View |
Page 2941 of 17672, showing 5 records out of 88360 total, starting on record 14701, ending on 14705