NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
72217  CVE-2004-1839  MS Analysis module 2.0 for PHP-Nuke allows remote attackers to obtain sensitive information via a direct request to (1) browsers.php, (2) mstrack.php, or (3) title.php, which reveal the full path in a PHP error message.    Medium  2016-12-20  2016-10-17  View
72985  CVE-2004-2608  SmartWebby Smart Guest Book stores SmartGuestBook.mdb (aka the "news database") under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the unencrypted username and password of the administrator"s account.    Medium  2016-12-20  2010-05-29  View
58905  CVE-2006-0165  Cross-site scripting (XSS) vulnerability in the DataForm Entries functionality in Plain Black WebGUI before 6.8.4 (gamma) allows remote attackers to inject arbitrary Javascript via the (1) url and (2) name field of the default email form.    4.3  Medium  2016-12-20  2011-03-07  View
59161  CVE-2006-0423  BEA WebLogic Portal 8.1 through SP3 stores the password for the RDBMS Authentication provider in cleartext in the config.xml file, which allows attackers to gain privileges.    7.5  High  2016-12-20  2011-03-07  View
59417  CVE-2006-0686  add_user.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not check user privileges when adding a new administrative user, which allows remote attackers to gain unauthorized access.    10  High  2016-12-20  2011-03-07  View

Page 140 of 17672, showing 5 records out of 88360 total, starting on record 696, ending on 700

Actions