NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 6235 | CVE-2008-6504 | ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Object-Graph Navigation Language (OGNL) statements and modify server-side context objects, as demonstrated by use of a u0023 representation for the # character. | 2 | 5 | Medium | 2017-01-03 | 2015-07-28 | View | |
| 71771 | CVE-2004-1392 | PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 6491 | CVE-2008-6760 | ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via an unauthenticated add and save action for a shopping cart in cart_save.php, which reveals the SQL table names in an error message, related to code that mishandles the lack of a user_id parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-28 | View | |
| 72027 | CVE-2004-1648 | Cross-site scripting (XSS) vulnerability in (1) index.asp, (2) ChangePassword.asp, (3) users_list.asp, (4) and users_add.asp in Password Protect allows remote attackers to inject arbitrary web script or HTML via the ShowMsg parameter. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 6747 | CVE-2008-7016 | tnftpd before 20080929 splits large command strings into multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unknown vectors, probably involving a crafted ftp:// link to a tnftpd server. | 2 | 6.8 | Medium | 2017-01-03 | 2009-08-21 | View |
Page 3261 of 17672, showing 5 records out of 88360 total, starting on record 16301, ending on 16305