NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86538 | CVE-2017-9378 | BigTree CMS through 4.2.18 does not prevent a user from deleting their own account. This could have security relevance because deletion was supposed to be an admin-only action, and the admin may have other tasks (such as data backups) to complete before a user is deleted. | 2 | 4 | Medium | 2017-06-12 | 2017-06-06 | View | |
86690 | CVE-2017-9444 | BigTree CMS through 4.2.18 has CSRF related to the coreadminmodulesusersprofileupdate.php script (modify user information), the index.php/admin/developer/packages/delete/ URI (remove packages), the index.php/admin/developer/upgrade/ignore/?versions= URI, and the index.php/admin/developer/upgrade/set-ftp-directory/ URI. | 2 | 6.8 | Medium | 2017-06-17 | 2017-06-12 | View | |
3185 | CVE-2008-3304 | BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to footer.php or (2) a direct request to pagination.php, which reveals the installation path in an error message. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
77363 | CVE-2000-1131 | Bill Kendrick web site guestbook (GBook) allows remote attackers to execute arbitrary commands via shell metacharacters in the _MAILTO form variable. | 2 | 7.5 | High | 2017-01-05 | 2008-09-05 | View | |
52631 | CVE-2007-0404 | bin/compile-messages.py in Django 0.95 does not quote argument strings before invoking the msgfmt program through the os.system function, which allows attackers to execute arbitrary commands via shell metacharacters in a (1) .po or (2) .mo file. | 2 | 7.5 | High | 2017-01-07 | 2008-09-05 | View |
Page 1538 of 17672, showing 5 records out of 88360 total, starting on record 7686, ending on 7690