CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25188  CVE-2007-1831  Candidate  web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to open files and write "wrong data" via a crafted QUERY_STRING.  Assigned (20070402)  None (candidate not yet proposed)    View
30583  CVE-2008-0466  Candidate  Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authentication, which allows remote attackers to list directories and read files. NOTE: this can be leveraged for listings outside the configured directory tree by exploiting a separate directory traversal vulnerability.  Assigned (20080128)  None (candidate not yet proposed)    View
42454  CVE-2009-5019  Candidate  Web Wiz NewsPad stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/NewsPad.mdb.  Assigned (20101201)  None (candidate not yet proposed)    View
8395  CVE-2003-1571  Candidate  Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database and obtain sensitive information via a direct request for database/WWGguestbook.mdb. NOTE: it was later reported that 8.21 is also affected.  Assigned (20090402)  None (candidate not yet proposed)    View
13434  CVE-2005-2228  Candidate  Web Wiz Forums 7.9 and 8.0 allows remote attackers to view message titles of a hidden forum.  Assigned (20050712)  None (candidate not yet proposed)    View

Page 396 of 20943, showing 5 records out of 104715 total, starting on record 1976, ending on 1980

Actions