NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
67164  CVE-2005-1425  Uapplication Uguestbook 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/guestbook.mdb.    Medium  2017-07-18  2017-07-10  View
2140  CVE-2008-2213  Multiple cross-site scripting (XSS) vulnerabilities in admin/inc/footer.php in Maian Links 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_script2 and (2) msg_script3 parameters.    4.3  Medium  2017-01-03  2009-01-29  View
67676  CVE-2005-1961  Unknown vulnerability in ObjectWeb Consortium C-JDBC before 1.3.1 allows local users to bypass intended access restrictions and obtain the cache results from another user.    4.6  Medium  2017-01-03  2008-09-05  View
2396  CVE-2008-2488  admin/userform.php in RoomPHPlanning 1.5 does not require administrative credentials, which allows remote authenticated users to create new admin accounts.    6.5  Medium  2017-01-03  2008-09-10  View
68188  CVE-2005-2498  Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.    Medium  2017-01-03  2016-10-17  View

Page 3296 of 17672, showing 5 records out of 88360 total, starting on record 16476, ending on 16480

Actions