NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
10011 | CVE-2011-3356 | Multiple cross-site scripting (XSS) vulnerabilities in config_defaults_inc.php in MantisBT before 1.2.8 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO, as demonstrated by the PATH_INFO to (1) manage_config_email_page.php, (2) manage_config_workflow_page.php, or (3) bugs/plugin.php. | 2 | 4.3 | Medium | 2017-01-07 | 2013-08-26 | View | |
75547 | CVE-1999-0897 | iChat ROOMS Webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack. | 2 | 5 | Medium | 2017-01-05 | 2016-10-17 | View | |
10267 | CVE-2011-3695 | 111WebCalendar 1.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by footer.php and certain other files. | 2 | 5 | Medium | 2017-01-07 | 2012-03-13 | View | |
10779 | CVE-2011-4311 | ResourceSpace before 4.2.2833 does not properly validate access keys, which allows remote attackers to bypass intended resource restrictions via unspecified vectors. | 2 | 5 | Medium | 2017-01-07 | 2011-11-21 | View | |
76315 | CVE-2000-0072 | Visual Casel (Vcasel) does not properly prevent users from executing files, which allows local users to use a relative pathname to specify an alternate file which has an approved name and possibly gain privileges. | 2 | 4.6 | Medium | 2017-01-05 | 2016-10-17 | View |
Page 980 of 17672, showing 5 records out of 88360 total, starting on record 4896, ending on 4900