NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
4334  CVE-2008-4511  Todd Woolums ASP News Management, possibly 2.21, stores db/news.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request.    Medium  2017-01-03  2009-01-29  View
69211  CVE-2005-3551  toendaCMS before 0.6.2 stores user account and session data in the web root directory, which allows remote attackers to obtain sensitive information via a direct request to the appropriate XML file.    Medium  2017-01-03  2011-03-07  View
68672  CVE-2005-3008  Tofu 0.2 allows remote attackers to execute arbitrary Python code via crafted pickled objects, which Tofu unpickles and executes.    7.5  High  2017-01-03  2008-09-05  View
4143  CVE-2008-4315  tog-pegasus in OpenGroup Pegasus 2.7.0 on Red Hat Enterprise Linux (RHEL) 5, Fedora 9, and Fedora 10 does not log failed authentication attempts to the OpenPegasus CIM server, which makes it easier for remote attackers to avoid detection of password guessing attacks.    6.8  Medium  2017-01-03  2010-08-21  View
50371  CVE-2009-3166  token.cgi in Bugzilla 3.4rc1 through 3.4.1 places a password in a URL at the beginning of a login session that occurs immediately after a password reset, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.    Medium  2017-01-07  2009-09-19  View

Page 15175 of 17672, showing 5 records out of 88360 total, starting on record 75871, ending on 75875

Actions