NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
43521  CVE-2012-1649  Cool Aid module before 6.x-1.9 for Drupal does not enforce access restrictions, which allows remote authenticated users with the administer coolaid permission to modify arbitrary pages via unspecified vectors.    4.9  Medium  2017-01-19  2012-09-10  View
44242  CVE-2012-2437  cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via the name parameter in conjunction with the content parameter.    Medium  2017-01-19  2013-08-17  View
29046  CVE-2014-0113  CookieInterceptor in Apache Struts before 2.3.16.2, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.    7.5  High  2017-01-19  2017-01-06  View
29048  CVE-2014-0116  CookieInterceptor in Apache Struts 2.x before 2.3.16.3, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and modify session state via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0113.    5.8  Medium  2017-01-19  2015-04-16  View
77481  CVE-2001-0001  cookiedecode function in PHP-Nuke 4.4 allows users to bypass authentication and gain access to other user accounts by extracting the authentication information from a cookie.    7.5  High  2017-01-05  2008-09-05  View

Page 15014 of 17672, showing 5 records out of 88360 total, starting on record 75066, ending on 75070

Actions