NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
44308 | CVE-2012-2566 | Bloxx Web Filtering before 5.0.14 does not properly interpret X-Forwarded-For headers during access-control and logging operations for HTTPS connection attempts, which allows remote attackers to bypass intended IP address and domain restrictions, and trigger misleading log entries, via a crafted header. | 2 | 5 | Medium | 2017-01-19 | 2012-08-18 | View | |
64252 | CVE-2006-5658 | BlooMooWeb ActiveX control (AidemATL.dll) allows remote attackers to (1) download arbitrary files via a URL in the bstrUrl parameter to the BW_DownloadFile method, (2) execute arbitrary local files via a file path in the bstrParams parameter to the BW_LaunchGame method, and (3) delete arbitrary files via a file path in the filePath parameter to the BW_DeleteTempFile method. | 2 | 7.6 | High | 2016-12-20 | 2011-03-07 | View | |
2432 | CVE-2008-2524 | BlogPHP 2.0 allows remote attackers to bypass authentication, and post (1) messages or (2) comments as an arbitrary user, via a modified blogphp_username field in a cookie. | 2 | 5 | Medium | 2017-01-03 | 2009-04-01 | View | |
48360 | CVE-2009-1050 | Bloginator 1A allows remote attackers to bypass authentication and gain administrative access by setting the identifyYourself cookie. | 2 | 7.5 | High | 2017-01-07 | 2009-04-03 | View | |
48141 | CVE-2009-0826 | BlogHelper stores common_db.inc under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request. | 2 | 5 | Medium | 2017-01-07 | 2009-03-06 | View |
Page 16110 of 17672, showing 5 records out of 88360 total, starting on record 80546, ending on 80550