NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
67595 | CVE-2005-1877 | Cross-site scripting (XSS) vulnerability in view_ticket.php in Lpanel 1.59 and earlier allows remote attackers to inject arbitrary web script or HTML and obtain sensitive information via the pid parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
67851 | CVE-2005-2147 | Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer scripts. | 2 | 6.4 | Medium | 2017-01-03 | 2008-09-05 | View | |
68107 | CVE-2005-2416 | Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
68363 | CVE-2005-2674 | ** DISPUTED ** Note: the vendor has disputed this issue. Multiple cross-site scripting (XSS) vulnerabilities in Land Down Under (LDU) 800 allow remote attackers to inject arbitrary web script or HTML via the (1) c or (2) m parameters to index.php or (3) w parameter to journal.php. NOTE: this issue has been disputed by the vendor, who says "None of the tricks written there are working, the variables are properly sanitized and no LDU version is affected." | 2 | 4.3 | Medium | 2017-01-03 | 2016-10-17 | View | |
68619 | CVE-2005-2955 | config.inc.php in ATutor 1.5.1, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which allows authenticated administrators or educators to execute arbitrary code by uploading files with other executable extensions such as .inc, .php4, or others. | 2 | 4.6 | Medium | 2017-01-03 | 2016-10-17 | View |
Page 400 of 17672, showing 5 records out of 88360 total, starting on record 1996, ending on 2000