NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
59993  CVE-2006-1279  CGI::Session 4.03-1 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by (1) Driver::File, (2) Driver::db_file, and possibly (3) Driver::sqlite.    Medium  2016-12-20  2011-03-07  View
35456  CVE-2014-8387  cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metacharacters in the pinghost parameter to ping.cgi.    High  2017-01-19  2014-11-20  View
1293  CVE-2008-1334  cgi/b on the BT Home Hub router allows remote attackers to bypass authentication, and read or modify administrative settings or make arbitrary VoIP telephone calls, by placing a character at the end of the PATH_INFO, as demonstrated by (1) %5C (encoded backslash), (2) "%" (percent), and (3) "~" (tilde). NOTE: the "/" (slash) vector is already covered by CVE-2007-5383.    7.5  High  2017-01-03  2008-10-11  View
46652  CVE-2012-5526  CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm.    Medium  2017-01-19  2016-12-07  View
79027  CVE-2002-0007  CGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bind to the LDAP server via a request that does not include a password, which causes a null password to be sent to the LDAP server.    10  High  2017-01-05  2008-09-10  View

Page 15325 of 17672, showing 5 records out of 88360 total, starting on record 76621, ending on 76625

Actions