NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
77781  CVE-2001-0303  tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to determine the physical path of the server via a URL that requests a non-existent file.    Medium  2017-01-05  2008-09-05  View
79213  CVE-2002-0203  ttawebtop.cgi in Tarantella Enterprise 3.20 on SPARC Solaris and Linux, and 3.1x and 3.0x including 3.11.903, allows remote attackers to view directory contents via an empty pg parameter.    Medium  2017-01-05  2016-10-17  View
52756  CVE-2007-0532  Tuan Do Uploader (aka php-uploader) 6 beta 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrator password hash via a direct request for userdata/user_1.txt.    Medium  2017-01-07  2008-09-05  View
51898  CVE-2009-4781  TUKEVA Password Reminder before 1.0.0.4 uses a hard-coded password for rem.accdb, which allows local users to discover credentials via a DBI connection.    7.2  High  2017-01-07  2010-04-22  View
85499  CVE-2017-7981  Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the proc_open PHP function is used within PhpWiki before 1.5.5 with a syntax value in its first argument, and an authenticated Tuleap user can control this value, even with shell metacharacters, as demonstrated by a '<?plugin SyntaxHighlighter syntax=c;id' line to execute the id command.    High  2017-05-27  2017-05-11  View

Page 15220 of 17672, showing 5 records out of 88360 total, starting on record 76096, ending on 76100

Actions