NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5352 | CVE-2008-5603 | ASPTicker 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for news.mdb. | 2 | 5 | Medium | 2017-01-03 | 2009-01-29 | View | |
48510 | CVE-2009-1223 | aspWebCalendar Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for calendar/calendar.mdb. | 2 | 5 | Medium | 2017-01-07 | 2009-04-18 | View | |
61492 | CVE-2006-2807 | ASPwebSoft Speedy Asp Discussion Forum allows remote attackers to change the password of any account via a modified account id and possibly arbitrary values of the name, email, country, password, and passwordre parameters to profileupdate.asp. | 2 | 10 | High | 2016-12-20 | 2008-09-05 | View | |
37687 | CVE-2013-1495 | asr in Oracle Auto Service Request in Oracle Support Tools before 4.3.2 allows local users to modify arbitrary files via a symlink attack on a predictable filename in /tmp. | 2 | 6.9 | Medium | 2017-01-18 | 2013-10-10 | View | |
35864 | CVE-2014-9044 | Asset Pipeline in ownCloud 7.x before 7.0.3 uses an MD5 hash of the absolute file paths of the original CSS and JS files as the name of the concatenated file, which allows remote attackers to obtain sensitive information via a brute force attack. | 2 | 5 | Medium | 2017-01-19 | 2015-02-05 | View |
Page 1433 of 17672, showing 5 records out of 88360 total, starting on record 7161, ending on 7165