NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
72217 | CVE-2004-1839 | MS Analysis module 2.0 for PHP-Nuke allows remote attackers to obtain sensitive information via a direct request to (1) browsers.php, (2) mstrack.php, or (3) title.php, which reveal the full path in a PHP error message. | 2 | 5 | Medium | 2016-12-20 | 2016-10-17 | View | |
72985 | CVE-2004-2608 | SmartWebby Smart Guest Book stores SmartGuestBook.mdb (aka the "news database") under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the unencrypted username and password of the administrator"s account. | 2 | 5 | Medium | 2016-12-20 | 2010-05-29 | View | |
58905 | CVE-2006-0165 | Cross-site scripting (XSS) vulnerability in the DataForm Entries functionality in Plain Black WebGUI before 6.8.4 (gamma) allows remote attackers to inject arbitrary Javascript via the (1) url and (2) name field of the default email form. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
59161 | CVE-2006-0423 | BEA WebLogic Portal 8.1 through SP3 stores the password for the RDBMS Authentication provider in cleartext in the config.xml file, which allows attackers to gain privileges. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
59417 | CVE-2006-0686 | add_user.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not check user privileges when adding a new administrative user, which allows remote attackers to gain unauthorized access. | 2 | 10 | High | 2016-12-20 | 2011-03-07 | View |
Page 140 of 17672, showing 5 records out of 88360 total, starting on record 696, ending on 700