NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86538  CVE-2017-9378  BigTree CMS through 4.2.18 does not prevent a user from deleting their own account. This could have security relevance because deletion was supposed to be an admin-only action, and the admin may have other tasks (such as data backups) to complete before a user is deleted.    Medium  2017-06-12  2017-06-06  View
86690  CVE-2017-9444  BigTree CMS through 4.2.18 has CSRF related to the coreadminmodulesusersprofileupdate.php script (modify user information), the index.php/admin/developer/packages/delete/ URI (remove packages), the index.php/admin/developer/upgrade/ignore/?versions= URI, and the index.php/admin/developer/upgrade/set-ftp-directory/ URI.    6.8  Medium  2017-06-17  2017-06-12  View
3185  CVE-2008-3304  BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to footer.php or (2) a direct request to pagination.php, which reveals the installation path in an error message.    Medium  2017-01-03  2008-09-05  View
77363  CVE-2000-1131  Bill Kendrick web site guestbook (GBook) allows remote attackers to execute arbitrary commands via shell metacharacters in the _MAILTO form variable.    7.5  High  2017-01-05  2008-09-05  View
52631  CVE-2007-0404  bin/compile-messages.py in Django 0.95 does not quote argument strings before invoking the msgfmt program through the os.system function, which allows attackers to execute arbitrary commands via shell metacharacters in a (1) .po or (2) .mo file.    7.5  High  2017-01-07  2008-09-05  View

Page 1538 of 17672, showing 5 records out of 88360 total, starting on record 7686, ending on 7690

Actions