NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 71982 | CVE-2004-1603 | cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 1228 | CVE-2008-1269 | cp06_wifi_m_nocifr.cgi in the admin panel on the Alice Gate 2 Plus Wi-Fi router does not verify authentication credentials, which allows remote attackers to disable Wi-Fi encryption via a certain request. | 2 | 7.1 | High | 2017-01-03 | 2008-09-05 | View | |
| 51108 | CVE-2009-3949 | cp/profile.php in VivaPrograms Infinity 2.0.5 and earlier does not require administrative authentication for the donewauthor action, which allows remote attackers to create administrative accounts via the name, password, and conf_password parameters. | 2 | 7.5 | High | 2017-01-07 | 2009-11-18 | View | |
| 58240 | CVE-2007-6237 | cp.php in DeluxeBB 1.09 does not verify that the membercookie parameter corresponds to the authenticated member during a profile update, which allows remote authenticated users to change the e-mail addresses of arbitrary accounts via a modified membercookie parameter, a different vector than CVE-2006-4078. NOTE: this can be leveraged for administrative access by requesting password-reset e-mail through a lostpw action to misc.php. | 2 | 9 | High | 2017-01-07 | 2008-09-05 | View | |
| 57087 | CVE-2007-4998 | cp, when running with an option to preserve symlinks on multiple OSes, allows local, user-assisted attackers to overwrite arbitrary files via a symlink attack using crafted directories containing multiple source files that are copied to the same destination. | 2 | 6.9 | Medium | 2017-01-07 | 2008-11-15 | View |
Page 14986 of 17672, showing 5 records out of 88360 total, starting on record 74926, ending on 74930