NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
65556  CVE-2006-7013  ** DISPUTED ** QueryString.php in Simple Machines Forum (SMF) 1.0.7 and earlier, and 1.1rc2 and earlier, allows remote attackers to more easily spoof the IP address and evade banning via a modified X-Forwarded-For HTTP header, which is preferred instead of other more reliable sources for the IP address. NOTE: the original researcher claims that the vendor has disputed this issue.    7.5  High  2016-12-20  2008-09-05  View
67477  CVE-2005-1753  ** DISPUTED ** ReadMessage.jsp in JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to view other users" e-mail attachments via a direct request to /mailboxesdir/username@domainname. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products."    Medium  2017-01-03  2016-10-17  View
63981  CVE-2006-5380  ** DISPUTED ** Remote file inclusion vulnerability in Contenido CMS allows remote attackers to execute arbitrary PHP code via a URL in the contenido_path parameter to (1) cms/dbfs.php or (2) cms/front_content.php. NOTE: CVE disputes this issue for version 4.6.15, because $contenido_path is set to a static value.    7.5  High  2016-12-20  2008-09-05  View
2386  CVE-2008-2478  ** DISPUTED ** scripts/wwwacct in cPanel 11.18.6 STABLE and earlier and 11.23.1 CURRENT and earlier allows remote authenticated users with reseller privileges to execute arbitrary code via shell metacharacters in the Email address field (aka Email text box). NOTE: the vendor disputes this, stating "I"m unable to reproduce such an issue on multiple servers running different versions of cPanel."    8.5  High  2017-01-03  2008-09-05  View
54790  CVE-2007-2626  ** DISPUTED ** SQL injection vulnerability in admin.php in SchoolBoard allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. NOTE: CVE disputes this issue, because "username" does not exist, and the password is not used in any queries.    7.5  High  2017-01-07  2008-11-15  View

Page 60 of 17672, showing 5 records out of 88360 total, starting on record 296, ending on 300

Actions