CVE List

Id CVE No. Status Description Phase Votes Comments Actions
37149  CVE-2008-7032  Candidate  Web Management Console Cross-site request forgery (CSRF) vulnerability in the web management console in F5 BIG-IP 9.4.3 allows remote attackers to hijack the authentication of administrators for requests that create new administrators and execute shell commands, as demonstrated using tmui/Control/form.  Assigned (20090823)  None (candidate not yet proposed)    View
9925  CVE-2004-1497  Candidate  Web Forums Server 1.6 and 2.0 Power Pack stores passwords in plaintext in the Username.ini file, which allows local users to gain privileges.  Assigned (20050218)  None (candidate not yet proposed)    View
38930  CVE-2009-1495  Candidate  Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/db.mdb.  Assigned (20090501)  None (candidate not yet proposed)    View
2824  CVE-2001-0003  Entry  Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability.        View
22009  CVE-2006-5905  Candidate  Web Directory Pro allows remote attackers to (1) backup the database and obtain the backup via a direct request to admin/backup_db.php or (2) modify configuration via a direct request to admin/options.php.  Assigned (20061115)  None (candidate not yet proposed)    View

Page 400 of 20943, showing 5 records out of 104715 total, starting on record 1996, ending on 2000

Actions