NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
67595  CVE-2005-1877  Cross-site scripting (XSS) vulnerability in view_ticket.php in Lpanel 1.59 and earlier allows remote attackers to inject arbitrary web script or HTML and obtain sensitive information via the pid parameter.    4.3  Medium  2017-01-03  2008-09-05  View
67851  CVE-2005-2147  Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer scripts.    6.4  Medium  2017-01-03  2008-09-05  View
68107  CVE-2005-2416  Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module.    4.3  Medium  2017-07-18  2017-07-10  View
68363  CVE-2005-2674  ** DISPUTED ** Note: the vendor has disputed this issue. Multiple cross-site scripting (XSS) vulnerabilities in Land Down Under (LDU) 800 allow remote attackers to inject arbitrary web script or HTML via the (1) c or (2) m parameters to index.php or (3) w parameter to journal.php. NOTE: this issue has been disputed by the vendor, who says "None of the tricks written there are working, the variables are properly sanitized and no LDU version is affected."    4.3  Medium  2017-01-03  2016-10-17  View
68619  CVE-2005-2955  config.inc.php in ATutor 1.5.1, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which allows authenticated administrators or educators to execute arbitrary code by uploading files with other executable extensions such as .inc, .php4, or others.    4.6  Medium  2017-01-03  2016-10-17  View

Page 400 of 17672, showing 5 records out of 88360 total, starting on record 1996, ending on 2000

Actions