NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
81286  CVE-2002-2335  Killer Protection 1.0 stores the vars.inc include file under the web root with insufficient access control, which allows remote attackers to obtain user names and passwords and log in using protection.php.    Medium  2017-01-05  2008-09-05  View
53638  CVE-2007-1454  ext/filter in PHP 5.2.0, when FILTER_SANITIZE_STRING is used with the FILTER_FLAG_STRIP_LOW flag, does not properly strip HTML tags, which allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML with a "<" character followed by certain whitespace characters, which passes one filter but is collapsed into a valid tag, as demonstrated using %0b.    4.3  Medium  2017-01-07  2008-09-05  View
57222  CVE-2007-5139  PHP remote file inclusion vulnerability in admin/include/header.php in chupix 0.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the repertoire parameter.    6.8  Medium  2017-01-07  2008-09-05  View
61062  CVE-2006-2360  SQL injection vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter.    7.5  High  2016-12-20  2008-09-05  View
61574  CVE-2006-2889  Multiple SQL injection vulnerabilities in index.php in Pixelpost 1-5rc1-2 and earlier allow remote attackers to execute arbitrary SQL commands, and leverage them to gain administrator privileges, via the (1) category or (2) archivedate parameter.    5.1  Medium  2016-12-20  2008-09-05  View

Page 898 of 17672, showing 5 records out of 88360 total, starting on record 4486, ending on 4490

Actions