NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
70018  CVE-2005-4420  Cross-site scripting (XSS) vulnerability in Honeycomb Archive Enterprise 3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keyword parameter in search.cfm.    4.3  Medium  2017-01-03  2008-09-20  View
70019  CVE-2005-4421  Dev-Editor 3.0 allows remote attackers to access any directory outside the web root whose name is a substring of the web root directory name.    7.5  High  2017-01-03  2011-03-07  View
70020  CVE-2005-4422  Unrestricted file upload vulnerability in toendaCMS before 0.6.2 Stable allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in data/images/albums.    6.5  Medium  2017-01-03  2008-09-05  View
70021  CVE-2005-4423  Unrestricted file upload vulnerability in PHPFM before 0.2.3 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension to an accessible directory, as demonstrated using a file with a .php extension, aka "upload phpshell."    6.5  Medium  2017-01-03  2008-09-05  View
70022  CVE-2005-4424  Directory traversal vulnerability in PHPKIT 1.6.1 R2 and earlier might allow remote authenticated users to execute arbitrary PHP code via a .. (dot dot) in the path parameter and a %00 at the end of the filename, as demonstrated by an avatar filename ending with .png%00.    6.5  Medium  2017-01-03  2008-09-05  View

Page 3028 of 17672, showing 5 records out of 88360 total, starting on record 15136, ending on 15140

Actions