NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
2792  CVE-2008-2898  Directory traversal vulnerability in includes/header.php in Hedgehog-CMS 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the c_temp_path parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.    9.3  High  2017-01-03  2009-04-14  View
68328  CVE-2005-2639  Buffer overflow in Chris Moneymaker"s World Poker Championship 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long nickname.    7.5  High  2017-01-03  2016-10-17  View
3048  CVE-2008-3164  Directory traversal vulnerability in blog.php in fuzzylime (cms) 3.01, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter. NOTE: it was later reported that 3.01a is also affected.    7.6  High  2017-01-03  2011-03-07  View
68584  CVE-2005-2916  Linksys WRT54G 3.01.03, 3.03.6, 4.00.7, and possibly other versions before 4.20.7, does not verify user authentication until after an HTTP POST request has been processed, which allows remote attackers to (1) modify configuration using restore.cgi or (2) upload new firmware using upgrade.cgi.    Medium  2017-01-03  2008-09-05  View
3304  CVE-2008-3423  IBM WebSphere Portal 5.1 through 6.1.0.0 allows remote attackers to bypass authentication and obtain administrative access via unspecified vectors.    7.5  High  2017-01-03  2011-03-07  View

Page 15694 of 17672, showing 5 records out of 88360 total, starting on record 78466, ending on 78470

Actions