NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
9490 | CVE-2011-2759 | The login page of IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation. | 2 | 5 | Medium | 2017-01-07 | 2011-09-06 | View | |
9489 | CVE-2011-2758 | IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not require authentication for access to LDAP Server log files, which allows remote attackers to obtain sensitive information via a crafted URL. | 2 | 5 | Medium | 2017-01-07 | 2011-07-19 | View | |
9488 | CVE-2011-2757 | Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the FILENAME parameter. NOTE: this might overlap the US-CERT VU#543310 issue. | 2 | 5 | Medium | 2017-01-07 | 2011-07-19 | View | |
9487 | CVE-2011-2756 | FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to read files from a specific directory via unspecified vectors. | 2 | 5 | Medium | 2017-01-07 | 2011-07-19 | View | |
9486 | CVE-2011-2755 | Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to read arbitrary files via unspecified vectors. | 2 | 5 | Medium | 2017-01-07 | 2011-07-19 | View |
Page 15775 of 17672, showing 5 records out of 88360 total, starting on record 78871, ending on 78875