NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
71942 | CVE-2004-1563 | Multiple cross-site scripting (XSS) vulnerabilities in w-Agora 4.1.6a allow remote attackers to execute arbitrary web script or HTML via the (1) thread parameter to download_thread.php, (2) loginuser parameter to login.php, or (3) userid parameter to forgot_password.php. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
6662 | CVE-2008-6931 | Unrestricted file upload vulnerability in PHPStore Job Search (aka PHPCareers) allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a resume photo, then accessing it via a direct request to the file in jobseekers/jobseeker_profile_images. | 2 | 6.5 | Medium | 2017-01-03 | 2009-08-19 | View | |
72198 | CVE-2004-1820 | PHP remote file inclusion vulnerability in displaycategory.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary PHP code by modifying the basepath parameter to reference a URL on a remote web server that contains fileFunctions.php. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
6918 | CVE-2008-7187 | Coppermine Photo Gallery (CPG) 1.4.14 allows remote attackers to obtain sensitive information via a direct request to include/slideshow.inc.php, which leaks the installation path in an error message. | 2 | 5 | Medium | 2017-01-03 | 2009-09-10 | View | |
72454 | CVE-2004-2077 | Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service (server crash) via malformed data to TCP port 2350, possibly due to long values or incorrect size fields. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 418 of 17672, showing 5 records out of 88360 total, starting on record 2086, ending on 2090