NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
70048  CVE-2005-4450  Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.7.0 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag to server_privileges.php, as demonstrated using the dbname and checkprivs parameters. NOTE: the provenance of this issue is unknown, although third parties imply that it is related to the disclosure of CVE-2005-4349, which was labeled as SQL injection but disputed.    7.5  High  2017-01-03  2008-09-05  View
70049  CVE-2005-4451  Unspecified vulnerability in Software Distributor in HP-UX B.11.11 allows remote attackers to gain access via unspecified attack vectors.    7.5  High  2017-01-03  2011-03-07  View
70050  CVE-2005-4452  Information Call Center stores the CallCenterData.mdb database under the web root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and passwords.    Medium  2017-01-03  2008-09-05  View
70051  CVE-2005-4453  UserProfile.cs in Ultraapps Issue Manager before 2.1 allows remote authenticated users to gain administrator privileges by modifying the original (1) p_User_user_id and (2) User_user_id parameters to UserProfile.aspx, then modifying the password field.    High  2017-01-03  2011-03-07  View
70052  CVE-2005-4454  Validate-before-filter vulnerability in cleanhtml.pl 1.129 in LiveJournal CVS before Dec 7 2005, when the cleancss option is enabled, allows remote attackers to conduct cross-site scripting (XSS) attacks via a "" (backslash) within a "javascript" scheme in a style property (such as "javascript"), which bypasses the "javascript" check before the "" is stripped and then rendered in web browsers that allow scripting in style sheets.    4.3  Medium  2017-01-03  2016-10-17  View

Page 3034 of 17672, showing 5 records out of 88360 total, starting on record 15166, ending on 15170

Actions