NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
56983 | CVE-2007-4893 | wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a does not properly verify the unfiltered_html privilege, which allows remote attackers to conduct cross-site scripting (XSS) attacks via modified data to (1) post.php or (2) page.php with a no_filter field. | 2 | 4.3 | Medium | 2017-01-07 | 2011-03-07 | View | |
10391 | CVE-2011-3819 | WoW Server Status 4.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by status.php and certain other files. | 2 | 5 | Medium | 2017-01-07 | 2012-05-21 | View | |
76973 | CVE-2000-0732 | Worm HTTP server allows remote attackers to cause a denial of service via a long URL. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
49273 | CVE-2009-2011 | Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a plug-in for Firefox, does not restrict access to the shell.execute JavaScript API method, which allows remote attackers to execute arbitrary commands via a .dxstudio file that invokes this method. | 2 | 9.3 | High | 2017-01-07 | 2009-06-22 | View | |
69864 | CVE-2005-4266 | WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a username, which allows remote attackers to perform actions as other users by guessing or sniffing the random value. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View |
Page 159 of 17672, showing 5 records out of 88360 total, starting on record 791, ending on 795