NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 66609 | CVE-2005-0859 | PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the tpath parameter to (1) headlines.php or (2) news.php. NOTE: some sources have reported the "dir" parameter as being affected; however, this is likely a cut-and-paste error from the wrong section of the original vulnerability report. Also, the news.php version was later reported to be in 1.12 through 1.14. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
| 1329 | CVE-2008-1371 | Absolute path traversal vulnerability in install/index.php in Drake CMS 0.4.11 RC8 allows remote attackers to read and execute arbitrary files via a full pathname in the d_root parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 3.6 | Low | 2017-01-03 | 2008-09-05 | View | |
| 66865 | CVE-2005-1116 | Cross-site scripting (XSS) vulnerability in the Calendar module for phpBB allow remote attackers to inject arbitrary web script or HTML via the start parameter to calendar_scheduler.php. | 2 | 4.3 | Medium | 2017-01-03 | 2016-10-17 | View | |
| 1585 | CVE-2008-1643 | Directory traversal vulnerability in the PXE TFTP Service (PXEMTFTP.exe) in LANDesk Management Suite (LDMS) 8.7 SP5 and earlier and 8.8 allows remote attackers to read arbitrary files via unspecified vectors. | 2 | 5 | Medium | 2017-01-03 | 2011-03-07 | View | |
| 67121 | CVE-2005-1382 | The webcacheadmin module in Oracle Webcache 9i allows remote attackers to corrupt arbitrary files via a full pathname in the cache_dump_file parameter. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 3324 of 17672, showing 5 records out of 88360 total, starting on record 16616, ending on 16620