NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
67931 | CVE-2005-2229 | Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directories with insufficient access control, which allows remote attackers to obtain sensitive information such as account names and password hashes, as demonstrated using data/newusers. | 2 | 7.5 | High | 2017-01-03 | 2016-10-17 | View | |
72724 | CVE-2004-2347 | blog.cgi in Leif M. Wright Web Blog 1.1 and 1.1.5 allows remote attackers to execute arbitrary commands via shell metacharacters such as '|' in the file parameter of ViewFile requests. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
47053 | CVE-2012-6105 | blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues to provide a blog RSS feed after blogging is disabled, which allows remote attackers to obtain sensitive information by reading this feed. | 2 | 5 | Medium | 2017-01-19 | 2013-01-28 | View | |
47052 | CVE-2012-6104 | blog/rsslib.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allows remote attackers to obtain sensitive information from site-level blogs by leveraging the guest role and reading an RSS feed. | 2 | 5 | Medium | 2017-01-19 | 2013-01-30 | View | |
41798 | CVE-2013-6953 | BlogEngine.NET 2.8.0.0 and earlier allows remote attackers to read usernames and password hashes via a request for the sioc.axd file. | 2 | 5 | Medium | 2017-01-18 | 2014-02-25 | View |
Page 1562 of 17672, showing 5 records out of 88360 total, starting on record 7806, ending on 7810