NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
80018 | CVE-2002-1022 | BadBlue server stores passwords in plaintext in the ext.ini file, which could allow local and possibly remote attackers to gain privileges. | 2 | 7.5 | High | 2017-01-05 | 2008-09-05 | View | |
40933 | CVE-2013-5674 | badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter. | 2 | 7.5 | High | 2017-01-18 | 2013-09-25 | View | |
29059 | CVE-2014-0129 | badges/mybadges.php in Moodle 2.5.x before 2.5.5 and 2.6.x before 2.6.2 does not properly track the user to whom a badge was issued, which allows remote authenticated users to modify the visibility of an arbitrary badge via unspecified vectors. | 2 | 4 | Medium | 2017-01-19 | 2014-03-24 | View | |
77785 | CVE-2001-0307 | Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist. | 2 | 7.5 | High | 2017-01-05 | 2008-09-05 | View | |
77014 | CVE-2000-0773 | Bajie HTTP web server 0.30a allows remote attackers to read arbitrary files via a URL that contains a "....", a variant of the dot dot directory traversal attack. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View |
Page 1490 of 17672, showing 5 records out of 88360 total, starting on record 7446, ending on 7450