CVE List

Id CVE No. Status Description Phase Votes Comments Actions
51953  CVE-2011-4041  Candidate  webvrpcs.exe in Advantech/BroadWin WebAccess allows remote attackers to execute arbitrary code or obtain a security-code value via a long string in an RPC request to TCP port 4592.  Assigned (20111013)  None (candidate not yet proposed)    View
38638  CVE-2009-1203  Candidate  WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 does not properly distinguish its own login screen from the login screens it produces for third-party (1) FTP and (2) CIFS servers, which makes it easier for remote attackers to trick a user into sending WebVPN credentials to an arbitrary server via a URL associated with that server, aka Bug ID CSCsy80709.  Assigned (20090331)  None (candidate not yet proposed)    View
38637  CVE-2009-1202  Candidate  WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass certain protection mechanisms involving URL rewriting and HTML rewriting, and conduct cross-site scripting (XSS) attacks, by modifying the first hex-encoded character in a /+CSCO+ URI, aka Bug ID CSCsy80705.  Assigned (20090331)  None (candidate not yet proposed)    View
76906  CVE-2014-9605  Candidate  WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a system backup tarball, restart the server, or stop the filters on the server via a " (single quote) character in the login and password parameters to webupgrade/webupgrade.php. NOTE: this was originally reported as an SQL injection vulnerability, but this may be inaccurate.  Assigned (20150116)  None (candidate not yet proposed)    View
23511  CVE-2007-0154  Candidate  Webulas stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/db.mdb.  Assigned (20070109)  None (candidate not yet proposed)    View

Page 229 of 20943, showing 5 records out of 104715 total, starting on record 1141, ending on 1145

Actions