NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
39841  CVE-2013-4193  typeswidget.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce the immutable setting on unspecified content edit forms, which allows remote attackers to hide fields on the forms via a crafted URL.    4.3  Medium  2017-01-18  2014-03-11  View
4694  CVE-2008-4905  Typo 5.1.3 and earlier uses a hard-coded salt for calculating password hashes, which makes it easier for attackers to guess passwords via a brute force attack.    Medium  2017-01-03  2009-01-29  View
59066  CVE-2006-0327  TYPO3 3.7.1 allows remote attackers to obtain sensitive information via a direct request to (1) thumbs.php, (2) showpic.php, or (3) tables.php, which causes them to incorrectly define a variable and reveal the path in an error message when a require function call fails.    Medium  2016-12-20  2011-03-07  View
70464  CVE-2005-4875  TYPO3 3.8.0 and earlier allows remote attackers to obtain sensitive information via a direct request to misc/phpcheck/, which invokes the phpinfo function and prints values of unspecified environment variables.    7.5  High  2017-01-03  2008-09-05  View
2615  CVE-2008-2717  TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote attackers to bypass security restrictions and upload configuration files such as .htaccess, or conduct file upload attacks using multiple extensions.    6.5  Medium  2017-07-18  2017-07-11  View

Page 15231 of 17672, showing 5 records out of 88360 total, starting on record 76151, ending on 76155

Actions