NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
778  CVE-2008-0807  lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware before 1.0.4 and Horde Groupware Webmail Edition before 1.0.5, does not properly check access rights, which allows remote authenticated users to modify address data via a modified object_id parameter to edit.php, as demonstrated by modifying a personal address book entry when there is write access to a shared address book.    4.9  Medium  2017-01-03  2011-03-07  View
1034  CVE-2008-1073  Cross-site scripting (XSS) vulnerability in the report interface in Internet Security Systems (ISS) Internet Scanner 7.0 Service Pack 2 Build 7.2.2005.52 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.    4.3  Medium  2017-01-03  2011-03-07  View
66570  CVE-2005-0820  Microsoft Office InfoPath 2003 SP1 includes sensitive information in the Manifest.xsf file in a custom .xsn form, which allows attackers to obtain printer and network information, obtain the database name, username, and password, or obtain the internal web server name.    Medium  2017-01-03  2008-09-05  View
1290  CVE-2008-1331  cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014.001, and other versions, allows remote attackers to execute arbitrary commands and "obtain OXO resources" via shell metacharacters in the id2 parameter.    10  High  2017-01-03  2011-03-07  View
66826  CVE-2005-1077  Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.4.x allow remote attackers to inject arbitrary web script or HTML via (1) cds.php, (2) Guestbook-EN.pl, or (3) phonebook.php.    4.3  Medium  2017-01-03  2016-10-17  View

Page 601 of 17672, showing 5 records out of 88360 total, starting on record 3001, ending on 3005

Actions