NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
44166  CVE-2012-2354  Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/site:readallmessages capability requirement and read arbitrary messages by using the "Recent conversations" feature with a modified parameter in a URL.    Medium  2017-01-19  2012-07-23  View
51590  CVE-2009-4467  misc.php in DeluxeBB 1.3 allows remote attackers to register accounts without a valid email address via a valemail action with the valmem set to a pre-assigned user ID, which is visible from a memberlist action.    Medium  2017-01-07  2009-12-30  View
55174  CVE-2007-3017  The WYSIWYG editor applet in activeWeb contentserver CMS before 5.6.2964 only filters malicious tags from articles sent to admin/applets/wysiwyg/rendereditor.asp, which allows remote authenticated users to inject arbitrary JavaScript via a request to admin/worklist/worklist_edit.asp.    Medium  2017-01-07  2008-11-15  View
61318  CVE-2006-2633  Absolute path traversal vulnerability in the copy action in index.php in Andrew Godwin ByteHoard 2.1 and earlier allows remote authenticated users to create or overwrite files in other users" directories by specifying the absolute path of the directory in the infolder parameter and simultaneously specifying the filename in the filepath parameter.    Medium  2016-12-20  2011-03-07  View
16775  CVE-2016-0323  The Auto-Scaling agent in Liberty for Java in IBM Bluemix before 2.7-20160321-1358 allows remote authenticated users to disable X.509 certificate validation, and consequently bypass an intended HTTPS trust-management feature, via unspecified vectors.    Medium  2017-01-19  2016-05-19  View

Page 14568 of 17672, showing 5 records out of 88360 total, starting on record 72836, ending on 72840

Actions