NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
66694 | CVE-2005-0945 | Cross-site scripting (XSS) vulnerability in ACS Blog 1.1.1 allows remote attackers to inject arbitrary web script or HTML via onmouseover or onload events in (1) img, (2) link, or (3) mail tags. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
66950 | CVE-2005-1201 | Multiple directory traversal vulnerabilities in AZ Bulletin board (AZbb) before 1.0.08 allow (1) remote authenticated users with administrative privileges to delete arbitrary files via a .. (dot dot) in the URL to admin_avatar.php or admin_attachment.php or (2) remote attackers to enumerate files via a .. (dot dot) in the attachment parameter to attachment.php, which displays a different message when a file exists or does not exist. | 2 | 6.4 | Medium | 2017-07-18 | 2017-07-10 | View | |
67974 | CVE-2005-2272 | Safari version 2.0 (412) does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability." | 2 | 2.6 | Low | 2017-07-18 | 2017-07-10 | View | |
69254 | CVE-2005-3596 | SQL injection vulnerability in ASPKnowledgebase allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password fields in adminlogin.asp. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
70534 | CVE-2004-0066 | phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (2) famlist.php, (3) placelist.php, (4) imageview.php, (5) timeline.php, (6) clippings.php, (7) login.php, and (8) gdbi.php. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 728 of 17672, showing 5 records out of 88360 total, starting on record 3636, ending on 3640