NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
74496  CVE-2003-1426  Openwebmail in cPanel 5.0, when run using suid Perl, adds the directory in the SCRIPT_FILENAME environment variable to Perl"s @INC include array, which allows local users to execute arbitrary code by modifying SCRIPT_FILENAME to reference a directory containing a malicious openwebmail-shared.pl executable.    3.3  Low  2017-01-03  2008-09-05  View
75776  CVE-1999-1126  Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_debug.log, (3) dbi_debug.log, and (4) temporary files whose names begin with "DPR_".    2.1  Low  2017-01-05  2008-09-05  View
77568  CVE-2001-0088  common.inc.php in phpWebLog 0.4.2 does not properly initialize the $CONF array, which inadvertently sets the password to a single character, allowing remote attackers to easily guess the SiteKey and gain administrative privileges to phpWebLog.    7.5  High  2017-01-05  2008-09-05  View
78080  CVE-2001-0615  Directory traversal vulnerability in Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to read arbitrary files via a specially crafted URL which includes variations of a ".." (dot dot) attack such as "..." or "....".    Medium  2017-01-05  2008-09-05  View
78592  CVE-2001-1157  Baltimore Technologies WEBsweeper 4.0 and 4.02 does not properly filter Javascript from HTML pages, which could allow remote attackers to bypass the filtering via (1) an extra leading < and one or more characters before the SCRIPT tag, or (2) tags using Unicode.    7.5  High  2017-01-05  2008-09-05  View

Page 16009 of 17672, showing 5 records out of 88360 total, starting on record 80041, ending on 80045

Actions