NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
44308  CVE-2012-2566  Bloxx Web Filtering before 5.0.14 does not properly interpret X-Forwarded-For headers during access-control and logging operations for HTTPS connection attempts, which allows remote attackers to bypass intended IP address and domain restrictions, and trigger misleading log entries, via a crafted header.    Medium  2017-01-19  2012-08-18  View
64252  CVE-2006-5658  BlooMooWeb ActiveX control (AidemATL.dll) allows remote attackers to (1) download arbitrary files via a URL in the bstrUrl parameter to the BW_DownloadFile method, (2) execute arbitrary local files via a file path in the bstrParams parameter to the BW_LaunchGame method, and (3) delete arbitrary files via a file path in the filePath parameter to the BW_DeleteTempFile method.    7.6  High  2016-12-20  2011-03-07  View
2432  CVE-2008-2524  BlogPHP 2.0 allows remote attackers to bypass authentication, and post (1) messages or (2) comments as an arbitrary user, via a modified blogphp_username field in a cookie.    Medium  2017-01-03  2009-04-01  View
48360  CVE-2009-1050  Bloginator 1A allows remote attackers to bypass authentication and gain administrative access by setting the identifyYourself cookie.    7.5  High  2017-01-07  2009-04-03  View
48141  CVE-2009-0826  BlogHelper stores common_db.inc under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request.    Medium  2017-01-07  2009-03-06  View

Page 16110 of 17672, showing 5 records out of 88360 total, starting on record 80546, ending on 80550

Actions