NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
68470 | CVE-2005-2783 | Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML via nested, malformed URL BBCode tags. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
70518 | CVE-2004-0050 | Verity Ultraseek before 5.2.2 allows remote attackers to obtain the full pathname of the document root via an MS-DOS device name in the web search option, such as (1) NUL, (2) CON, (3) AUX, (4) COM1, (5) COM2, and others. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
70774 | CVE-2004-0323 | Multiple SQL injection vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to inject arbitrary SQL and gain privileges via the (1) ppp parameter in viewthread.php, (2) desc parameter in misc.php, (3) tpp parameter in forumdisplay.php, (4) ascdesc parameter in forumdisplay.php, or (5) the addon parameter in stats.php. NOTE: it has also been shown that item (3) is also in XMB 1.9 beta. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
71030 | CVE-2004-0603 | gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users to execute arbitrary commands, a different vulnerability than CVE-1999-1332. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View | |
71286 | CVE-2004-0880 | getmail 4.x before 4.2.0, when run as root, allows local users to overwrite arbitrary files via a symlink attack on an mbox file. | 2 | 1.2 | Low | 2017-07-18 | 2017-07-10 | View |
Page 687 of 17672, showing 5 records out of 88360 total, starting on record 3431, ending on 3435