NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 4014 | CVE-2008-4158 | Multiple directory traversal vulnerabilities in index.php in Zanfi CMS lite 1.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) flag and (2) inc parameters. | 2 | 6.8 | Medium | 2017-01-03 | 2009-01-29 | View | |
| 69550 | CVE-2005-3912 | Format string vulnerability in miniserv.pl Perl web server in Webmin before 1.250 and Usermin before 1.180, with syslog logging enabled, allows remote attackers to cause a denial of service (crash or memory consumption) and possibly execute arbitrary code via format string specifiers in the username parameter to the login form, which is ultimately used in a syslog call. NOTE: the code execution might be associated with an issue in Perl. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
| 4270 | CVE-2008-4447 | Cross-site scripting (XSS) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to inject arbitrary web script or HTML via (1) the fn parameter during a dload action, (2) the mask parameter during a search action, and (3) the tab parameter during a sysinfo action. | 2 | 4.3 | Medium | 2017-01-03 | 2009-03-03 | View | |
| 69806 | CVE-2005-4208 | Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a .. (dot dot) and null byte (%00) in the id parameter of the read module. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
| 4526 | CVE-2008-4712 | Directory traversal vulnerability in pages/showblog.php in LnBlog 0.9.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the plugin parameter. | 2 | 6.8 | Medium | 2017-01-03 | 2009-01-29 | View |
Page 3092 of 17672, showing 5 records out of 88360 total, starting on record 15456, ending on 15460