CVE List

Id CVE No. Status Description Phase Votes Comments Actions
51728  CVE-2011-3816  Candidate  WEBinsta mailing list manager 1.3e allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by install/install3.php and certain other files.  Assigned (20110923)  None (candidate not yet proposed)    View
32803  CVE-2008-2686  Candidate  webinc/bxe/scripts/loadsave.php in Flux CMS 1.5.0 and earlier allows remote attackers to execute arbitrary code by overwriting a PHP file in webinc/bxe/scripts/ via a filename in the XML parameter and PHP sequences in the request body, then making a direct request for this filename.  Assigned (20080613)  None (candidate not yet proposed)    View
4265  CVE-2001-1462  Candidate  WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to cause the WebID agent to enter debug mode via a URL containing null characters, which may allow attackers to obtain sensitive information.  Assigned (20050421)  None (candidate not yet proposed)    View
37235  CVE-2008-7118  Candidate  WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain SQL query logs via a direct request for logs/cron.log.  Assigned (20090828)  None (candidate not yet proposed)    View
72411  CVE-2014-5114  Candidate  WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter.  Assigned (20140729)  None (candidate not yet proposed)    View

Page 381 of 20943, showing 5 records out of 104715 total, starting on record 1901, ending on 1905

Actions