NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
68371 | CVE-2005-2682 | aspell_setup.php in the SpellChecker plugin in DTLink AreaEdit before 0.4.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the dictionary parameter (aka the lang variable). | 2 | 7.5 | High | 2017-01-03 | 2008-09-10 | View | |
68627 | CVE-2005-2963 | The mod_auth_shadow module 1.0 through 1.5 and 2.0 for Apache with AuthShadow enabled uses shadow authentication for all locations that use the require group directive, even when other authentication mechanisms are specified, which might allow remote authenticated users to bypass security restrictions. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
3347 | CVE-2008-3473 | Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, via a crafted HTML document, aka "Event Handling Cross-Domain Vulnerability." | 2 | 9.3 | High | 2017-01-03 | 2012-01-26 | View | |
69139 | CVE-2005-3478 | SQL injection vulnerability in index.php in PHPCafe.net Tutorials Manager 1.0 Beta 2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
69395 | CVE-2005-3757 | The Saxon XSLT parser in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to obtain sensitive information and execute arbitrary code via dangerous Java class methods in select attribute of xsl:value-of tags in XSLT style sheets, such as (1) system-property, (2) sys:getProperty, and (3) run:exec. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View |
Page 862 of 17672, showing 5 records out of 88360 total, starting on record 4306, ending on 4310