CVE List

Id CVE No. Status Description Phase Votes Comments Actions
23689  CVE-2007-0332  Candidate  (1) admin/adminlien.php3 and (2) admin/modif.php3 in liens_dynamiques 2.1 do not require authentication, which allows remote attackers to perform unauthorized administrative actions using a direct request.  Assigned (20070117)  None (candidate not yet proposed)    View
56598  CVE-2012-3355  Candidate  (1) AlbumTab.py, (2) ArtistTab.py, (3) LinksTab.py, and (4) LyricsTab.py in the Context module in GNOME Rhythmbox 0.13.3 and earlier allows local users to execute arbitrary code via a symlink attack on a temporary HTML template file in the /tmp/context directory.  Assigned (20120614)  None (candidate not yet proposed)    View
18721  CVE-2006-2617  Candidate  (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote attackers to obtain the installation path via an invalid entry in the Username field on the login page, which causes the path to be displayed in an SQL error. NOTE: this issue might be resultant from SQL injection.  Assigned (20060525)  None (candidate not yet proposed)    View
20756  CVE-2006-4652  Candidate  (1) Amazing Little Poll and (2) Amazing Little Picture Poll have a default password of "dsapoll", which allows remote attackers to create a new poll by entering default credentials via lp_admin.php.  Assigned (20060908)  None (candidate not yet proposed)    View
20757  CVE-2006-4653  Candidate  (1) Amazing Little Poll and (2) Amazing Little Picture Poll store sensitive information under the web root with insufficient access control, which allows remote attackers to read the admin password via a direct request for the lp_settings file (lp_settings.inc or lp_settings.php).  Assigned (20060908)  None (candidate not yet proposed)    View

Page 2 of 20943, showing 5 records out of 104715 total, starting on record 6, ending on 10

<<first 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 last>>

Actions