CVE List

Id CVE No. Status Description Phase Votes Comments Actions
22564  CVE-2006-6460  Candidate  Yourfreeworld.com Short Url & Url Tracker Script allows remote attackers to obtain sensitive information via an invalid id parameter to login.php, which leaks the path in an error message. NOTE: this issue might be resultant from CVE-2006-2509.  Assigned (20061211)  None (candidate not yet proposed)    View
36888  CVE-2008-6771  Candidate  YourPlace 1.0.2 and earlier allows remote attackers to obtain sensitive system information via a direct request via a direct request to user/uploads/phpinfo.php, which calls the phpinfo function.  Assigned (20090429)  None (candidate not yet proposed)    View
36887  CVE-2008-6770  Candidate  YourPlace 1.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to a database containing user credentials via a direct request for users.txt.  Assigned (20090429)  None (candidate not yet proposed)    View
42201  CVE-2009-4766  Candidate  YP Portal MS-Pro Surumu (aka MS-Pro Portal Scripti) 1.0 and 1.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for galeri/database/db.mdb.  Assigned (20100413)  None (candidate not yet proposed)    View
6385  CVE-2002-2003  Candidate  ypbind in Compaq Tru64 4.0F, 4.0G, 5.0A, 5.1 and 5.1A allows remote attackers to cause the process to core dump via certain network packets generated by nmap.  Assigned (20050714)  None (candidate not yet proposed)    View

Page 20904 of 20943, showing 5 records out of 104715 total, starting on record 104516, ending on 104520

Actions