NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
72203 | CVE-2004-1825 | Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) return or (2) mos_change_template parameters. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
6923 | CVE-2008-7192 | Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board (wBB) 3.0.1, and possibly other 3.x versions, allows remote attackers to hijack the authentication of users for requests that delete private messages via the pmID parameter in a delete action in a PM page, a different vulnerability than CVE-2008-0472. | 2 | 6.8 | Medium | 2017-01-03 | 2009-09-28 | View | |
72459 | CVE-2004-2082 | The samiftp.dll library in Sami FTP Server 1.1.3 allows remote authenticated users to cause a denial of service (pmsystem.exe crash) via a GET request wit a large number of leading "/" (slash) characters. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
7435 | CVE-2011-0344 | Multiple stack-based buffer overflows in unspecified CGI programs in the Unified Maintenance Tool web interface in the embedded web server in the Communication Server (CS) in Alcatel-Lucent OmniPCX Enterprise before R9.0 H1.301.50 allow remote attackers to execute arbitrary code via crafted HTTP headers. | 2 | 5.8 | Medium | 2017-01-07 | 2011-03-17 | View | |
72971 | CVE-2004-2594 | Absolute path traversal vulnerability in Quake II server before R1Q2 on Windows, as used in multiple products, allows remote attackers to read arbitrary files via a / in a pathname argument, as demonstrated by download /server.cfg. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 403 of 17672, showing 5 records out of 88360 total, starting on record 2011, ending on 2015