NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
1806 | CVE-2008-1866 | admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to upload arbitrary PHP scripts in a ZIP archive, which is written to templateZip/ and then automatically extracted under templates/ for execution via a direct request. | 2 | 9 | High | 2017-01-03 | 2011-03-07 | View | |
67342 | CVE-2005-1615 | viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 may allow remote attackers to read sensitive data via the postorder parameter, which is not properly handled by textdb.inc.php, possibly due to a SQL injection vulnerability. | 2 | 7.5 | High | 2017-01-03 | 2016-10-17 | View | |
2062 | CVE-2008-2128 | PHP remote file inclusion vulnerability in templates/header.php in CMS Faethon 2.2 Ultimate allows remote attackers to execute arbitrary PHP code via a URL in the mainpath parameter, a different vulnerability than CVE-2006-5588 and CVE-2006-3185. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
67598 | CVE-2005-1880 | everybuddy 0.4.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget. | 2 | 2.1 | Low | 2017-01-03 | 2008-09-05 | View | |
2318 | CVE-2008-2402 | The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read password hashes and configuration data via direct requests for unspecified documents. | 2 | 5 | Medium | 2017-01-03 | 2011-03-07 | View |
Page 1305 of 17672, showing 5 records out of 88360 total, starting on record 6521, ending on 6525