NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
307 | CVE-2008-0329 | LulieBlog 1.0.1 and 1.0.2 does not restrict access to (1) article_suppr.php, (2) comment_accepter.php, and (3) comment_refuser.php in Admin/, which allows remote attackers to accept comments, delete comments, and delete articles via the id parameter. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
819 | CVE-2008-0848 | Cross-site scripting (XSS) vulnerability in lostsheep.php in Crafty Syntax Live Help (CSLH) before 2.14.16, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the versions claimed by the original researcher are probably incorrect. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
67379 | CVE-2005-1654 | Hosting Controller 6.1 Hotfix 1.9 and earlier allows remote attackers to register arbitrary users via a direct request to addsubsite.asp with the loginname and password parameters set. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
67635 | CVE-2005-1917 | kpopper 1.0 and earlier allows local users to create and overwrite arbitrary files via a symlink attack on the .popper-new temporary file. | 2 | 2.1 | Low | 2017-01-03 | 2008-09-05 | View | |
69939 | CVE-2005-4341 | Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to list all available categories via a blank category_id parameter to category.pl. NOTE: it is not clear whether this information is sensitive or not, so this might not be an exposure. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 327 of 17672, showing 5 records out of 88360 total, starting on record 1631, ending on 1635