NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
41672  CVE-2013-6788  The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it easier for remote attackers to guess the cookie value and bypass authentication via a brute force attack.    7.5  High  2017-01-18  2014-06-26  View
41928  CVE-2013-7137  The "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and gain privileges by setting the burden_user_rememberme cookie to 1.    7.5  High  2017-01-18  2014-02-24  View
43208  CVE-2012-1205  PHP remote file inclusion vulnerability in relocate-upload.php in Relocate Upload plugin before 0.20 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.    7.5  High  2017-01-19  2012-02-24  View
49608  CVE-2009-2361  SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the staff username parameter.    7.5  High  2017-01-07  2009-07-22  View
50888  CVE-2009-3702  Multiple absolute path traversal vulnerabilities in PHP-Calendar 1.1 allow remote attackers to include and execute arbitrary local files via a full pathname in the configfile parameter to (1) update08.php or (2) update10.php. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.    7.5  High  2017-01-07  2009-12-22  View

Page 15065 of 17672, showing 5 records out of 88360 total, starting on record 75321, ending on 75325

Actions