NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
78546 | CVE-2001-1111 | EFTP 2.0.7.337 stores user passwords in plaintext in the eftp2users.dat file. | 2 | 4.6 | Medium | 2017-01-05 | 2008-09-05 | View | |
79314 | CVE-2002-0304 | Lil HTTP Server 2.1 allows remote attackers to read password-protected files via a /./ in the HTTP request. | 2 | 5 | Medium | 2017-01-05 | 2016-10-17 | View | |
79570 | CVE-2002-0565 | Oracle 9iAS 1.0.2.x compiles JSP files in the _pages directory with world-readable permissions under the web root, which allows remote attackers to obtain sensitive information derived from the JSP code, including usernames and passwords, via a direct HTTP request to _pages. | 2 | 5 | Medium | 2017-01-05 | 2016-10-17 | View | |
14290 | CVE-2010-2856 | Cross-site scripting (XSS) vulnerability in admin/currencies.php in osCSS 1.2.2, and probably earlier versions, allows remote attackers to inject arbitrary web script or HTML via the page parameter. | 2 | 4.3 | Medium | 2017-01-18 | 2013-08-23 | View | |
80082 | CVE-2002-1087 | The scripts (1) createdir.php, (2) removedir.php and (3) uploadfile.php for ezContents 1.41 and earlier do not check credentials, which allows remote attackers to create or delete directories and upload files via a direct HTTP POST request. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View |
Page 16045 of 17672, showing 5 records out of 88360 total, starting on record 80221, ending on 80225