NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
67719 | CVE-2005-2007 | Directory traversal vulnerability in Edgewall Trac 0.8.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the id parameter to the (1) upload or (2) attachment scripts. | 2 | 6.4 | Medium | 2017-01-03 | 2008-09-05 | View | |
67975 | CVE-2005-2273 | Opera 7.x and 8 before 8.01 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability." | 2 | 2.6 | Low | 2017-01-03 | 2008-09-05 | View | |
68743 | CVE-2005-3080 | contrib/example.php in GeSHi before 1.0.7.3 allows remote attackers to read arbitrary files via the language field without a source field set. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
68999 | CVE-2005-3337 | Multiple cross-site scripting (XSS) vulnerabilities in Mantis before 0.19.3 allow remote attackers to inject arbitrary web script or HTML via (1) unknown vectors involving Javascript and (2) mantis/view_all_set.php. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
69767 | CVE-2005-4159 | ** DISPUTED ** NOTE: this issue has been disputed by the vendor and third parties. SQL injection vulnerability in Memberlist.php in Simple Machines Forum (SMF) 1.1 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter. NOTE: the vendor says that since only one character can be modified, there is no SQL injection. Thus this might be an "invalid SQL syntax error." Multiple followups support the vendor. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View |
Page 900 of 17672, showing 5 records out of 88360 total, starting on record 4496, ending on 4500