CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
70598 | CVE-2014-3302 | Candidate | user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCuj81708. | Assigned (20140507) | None (candidate not yet proposed) | View | |
13802 | CVE-2005-2596 | Candidate | User.php in Gallery, as used in Postnuke, allows users with any Admin privileges to gain access to all galleries. | Assigned (20050817) | None (candidate not yet proposed) | View | |
23981 | CVE-2007-0624 | Candidate | user.php in MAXdev MDPro 1.0.76 allows remote attackers to obtain the full path via a " (quote) character, and possibly other invalid values, in the uname parameter in a userinfo operation. | Assigned (20070131) | None (candidate not yet proposed) | View | |
54845 | CVE-2012-1602 | Candidate | user.php in NextBBS 0.6 allows remote attackers to bypass authentication and gain administrator access by setting the userkey cookie to 1. | Assigned (20120312) | None (candidate not yet proposed) | View | |
27500 | CVE-2007-4143 | Candidate | user.php in the Billing Control Panel in phpCoupon allows remote authenticated users to obtain Premium Member status, and possibly acquire free coupons, via a modified URL containing a certain billing parameter and REQ=auth, status=success, and custom=upgrade substrings, possibly related to PayPal transactions. | Assigned (20070803) | None (candidate not yet proposed) | View |
Page 20354 of 20943, showing 5 records out of 104715 total, starting on record 101766, ending on 101770