NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
6939 | CVE-2008-7208 | Multiple SQL injection vulnerabilities in OneCMS 2.4, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) username parameter ($usernameb variable) to a_login.php or (2) user parameter to staff.php. | 2 | 6.8 | Medium | 2017-01-03 | 2009-09-15 | View | |
72475 | CVE-2004-2098 | Cross-site scripting (XSS) vulnerability in the banner engine (TBE) 5.0 allows remote attackers to execute arbitrary script as other users via the HTML banner view/preview capability. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
7195 | CVE-2011-0059 | Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to hijack the authentication of arbitrary users for requests that were initiated by a plugin and received a 307 redirect to a page on a different web site. | 2 | 6.8 | Medium | 2017-01-07 | 2017-01-06 | View | |
72731 | CVE-2004-2354 | SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL statements via the entry parameter to modules.php, which can also facilitate cross-site scripting (XSS) attacks when MySQL errors are triggered. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
72987 | CVE-2004-2610 | mntd_mount.c in mntd before 0.4.2 might allow local users to gain privileges via shell metacharacters in a remount option in the configuration file. NOTE: It is not clear whether this is a vulnerability because there is not necessarily any common usage in which privilege boundaries are crossed. Typical usage would restrict write access to the configuration file. | 2 | 4.6 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 977 of 17672, showing 5 records out of 88360 total, starting on record 4881, ending on 4885