NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
274 | CVE-2008-0289 | PHP remote file inclusion vulnerability in view_func.php in Member Area System (MAS) 1.7 and possibly others allows remote attackers to execute arbitrary PHP code via a URL in the i parameter. NOTE: a second vector might exist via the l parameter. NOTE: as of 20080118, the vendor has disputed the set of affected versions, stating that the issue "is already fixed, for almost a year." | 2 | 6.8 | Medium | 2017-01-03 | 2008-09-05 | View | |
66066 | CVE-2005-0303 | Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_supportError.asp or (2) comersus_backofficelite_supportError.asp in BackOffice Lite 6.0 and 6.01 allow remote attackers to inject arbitrary web script or HTML via the error parameter. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
66322 | CVE-2005-0570 | profile.php in PunBB 1.2.1 allows remote attackers to cause a denial of service (account lockout) by setting the user's password to NULL. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
1042 | CVE-2008-1081 | Opera before 9.26 allows user-assisted remote attackers to execute arbitrary script via images that contain custom comments, which are treated as script when the user displays the image properties. | 2 | 6.8 | Medium | 2017-01-03 | 2012-06-07 | View | |
66578 | CVE-2005-0828 | highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allows remote attackers to read arbitrary PHP files by specifying the pathname in the file parameter, as demonstrated by reading database configuration information from mainfile.php. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 651 of 17672, showing 5 records out of 88360 total, starting on record 3251, ending on 3255