CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
51728 | CVE-2011-3816 | Candidate | WEBinsta mailing list manager 1.3e allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by install/install3.php and certain other files. | Assigned (20110923) | None (candidate not yet proposed) | View | |
32803 | CVE-2008-2686 | Candidate | webinc/bxe/scripts/loadsave.php in Flux CMS 1.5.0 and earlier allows remote attackers to execute arbitrary code by overwriting a PHP file in webinc/bxe/scripts/ via a filename in the XML parameter and PHP sequences in the request body, then making a direct request for this filename. | Assigned (20080613) | None (candidate not yet proposed) | View | |
4265 | CVE-2001-1462 | Candidate | WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to cause the WebID agent to enter debug mode via a URL containing null characters, which may allow attackers to obtain sensitive information. | Assigned (20050421) | None (candidate not yet proposed) | View | |
37235 | CVE-2008-7118 | Candidate | WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain SQL query logs via a direct request for logs/cron.log. | Assigned (20090828) | None (candidate not yet proposed) | View | |
72411 | CVE-2014-5114 | Candidate | WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter. | Assigned (20140729) | None (candidate not yet proposed) | View |
Page 381 of 20943, showing 5 records out of 104715 total, starting on record 1901, ending on 1905