NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
80388  CVE-2002-1435  class.atkdateattribute.js.php in Achievo 0.7.0 through 0.9.1, except 0.8.2, allows remote attackers to execute arbitrary PHP code when the "allow_url_fopen" setting is enabled via a URL in the config_atkroot parameter that points to the code.    7.5  High  2017-01-05  2008-09-05  View
59149  CVE-2006-0411  claro_init_local.inc.php in Claroline 1.7.2 uses guessable session cookies (MD5 hash of connection time), which allows remote attackers to hijack sessions and possibly gain administrative privileges.    10  High  2016-12-20  2011-03-07  View
56859  CVE-2007-4742  Claroline before 1.8.6 allows remote authenticated administrators to obtain sensitive information via an invalid value in the sort parameter to admin/adminusers.php, which reveals the path in an error message in some circumstances, as demonstrated by a parameter value containing an XSS sequence.    4.3  Medium  2017-01-07  2012-10-29  View
10288  CVE-2011-3716  Claroline 1.9.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by work/connector/linker.cnr.php and certain other files.    Medium  2017-01-07  2012-03-13  View
74449  CVE-2003-1379  clarkconnectd in ClarkConnect Linux 1.2 allows remote attackers to obtain sensitive information about the server via the characters (1) A, which reveals the date and time, (2) F, (3) M, which reveals "ifconfig" information, (4) P, which lists the processes, (5) Y, which reveals the snort log files, or (6) b, which reveals /var/log/messages.    Medium  2017-01-03  2008-09-05  View

Page 15089 of 17672, showing 5 records out of 88360 total, starting on record 75441, ending on 75445

Actions