NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
71779  CVE-2004-1400  The control panel in ASP Calendar does not require authentication to access, which allows remote attackers to gain unauthorized access via a direct request to main.asp.    7.5  High  2017-07-18  2017-07-10  View
72035  CVE-2004-1656  CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the redirecturl parameter.    Medium  2017-07-18  2017-07-10  View
72291  CVE-2004-1913  Cross-site scripting (XSS) vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to inject arbitrary web script or HTML via the eid parameter.    4.3  Medium  2017-07-18  2017-07-10  View
72547  CVE-2004-2170  Directory traversal vulnerability in sample_showcode.html in Caravan 2.00/03d and earlier allows remote attackers to read arbitrary files via the fname parameter.    Medium  2017-07-18  2017-07-10  View
72803  CVE-2004-2426  Directory traversal vulnerability in Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to bypass authentication via a .. (dot dot) in an HTTP POST request to ServerManager.srv, then use these privileges to conduct other activities, such as modifying files using editcgi.cgi.    Medium  2017-07-18  2017-07-10  View

Page 550 of 17672, showing 5 records out of 88360 total, starting on record 2746, ending on 2750

Actions