NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 70018 | CVE-2005-4420 | Cross-site scripting (XSS) vulnerability in Honeycomb Archive Enterprise 3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keyword parameter in search.cfm. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-20 | View | |
| 70019 | CVE-2005-4421 | Dev-Editor 3.0 allows remote attackers to access any directory outside the web root whose name is a substring of the web root directory name. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
| 70020 | CVE-2005-4422 | Unrestricted file upload vulnerability in toendaCMS before 0.6.2 Stable allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in data/images/albums. | 2 | 6.5 | Medium | 2017-01-03 | 2008-09-05 | View | |
| 70021 | CVE-2005-4423 | Unrestricted file upload vulnerability in PHPFM before 0.2.3 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension to an accessible directory, as demonstrated using a file with a .php extension, aka "upload phpshell." | 2 | 6.5 | Medium | 2017-01-03 | 2008-09-05 | View | |
| 70022 | CVE-2005-4424 | Directory traversal vulnerability in PHPKIT 1.6.1 R2 and earlier might allow remote authenticated users to execute arbitrary PHP code via a .. (dot dot) in the path parameter and a %00 at the end of the filename, as demonstrated by an avatar filename ending with .png%00. | 2 | 6.5 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 3028 of 17672, showing 5 records out of 88360 total, starting on record 15136, ending on 15140