NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
66573 | CVE-2005-0823 | ThePoolClub (1) iPool and (2) iSnooker 1.6.81 and earlier stores usernames and passwords in cleartext in the MyDetails.txt file, which allows local users to gain privileges. | 2 | 4.6 | Medium | 2017-07-18 | 2017-07-10 | View | |
66829 | CVE-2005-1080 | Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in filenames in a .jar file. | 2 | 5 | Medium | 2017-01-03 | 2017-01-02 | View | |
1549 | CVE-2008-1606 | Multiple directory traversal vulnerabilities in Elastic Path (EP) 4.1 and 4.1.1 allow remote attackers to (1) download arbitrary files via a .. (dot dot) in the file parameter to manager/getImportFileRedirect.jsp, (2) upload arbitrary files via a ".." (dot dot backslash) in the file parameter to importData.jsp, and (3) list directory contents via a .. (dot dot) in the dir parameter to manager/fileManager.jsp. | 2 | 6 | Medium | 2017-01-03 | 2011-03-07 | View | |
67341 | CVE-2005-1614 | Cross-site scripting (XSS) vulnerability in viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the postorder parameter. | 2 | 6.8 | Medium | 2017-01-03 | 2016-10-17 | View | |
2061 | CVE-2008-2127 | Cross-site scripting (XSS) vulnerability in search.php in CMS Faethon 2.2 Ultimate allows remote attackers to inject arbitrary web script or HTML via the what parameter. NOTE: some of these details are obtained from third party information. | 2 | 4.3 | Medium | 2017-01-03 | 2008-11-26 | View |
Page 472 of 17672, showing 5 records out of 88360 total, starting on record 2356, ending on 2360