NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84976  CVE-2017-7881  BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the required admin/developer/ URI within a query string in an HTTP Referer header. This was found in core/admin/modules/developer/_header.php and patched in core/inc/bigtree/admin.php on 2017-04-14.    6.8  Medium  2017-04-27  2017-04-21  View
79468  CVE-2002-0462  bigsam_guestbook.php for Big Sam (Built-In Guestbook Stand-Alone Module) 1.1.08 and earlier allows remote attackers to cause a denial of service (CPU consumption) or obtain the absolute path of the web server via a displayBegin parameter with a very large number, which leaks the web path in an error message when PHP safe_mode is enabled, or consumes resources when safe_mode is not enabled.    6.4  Medium  2017-01-05  2008-09-05  View
76200  CVE-1999-1550  bigconf.conf in F5 BIG/ip 2.1.2 and earlier allows remote attackers to read arbitrary files by specifying the target file in the "file" parameter.    Medium  2017-01-05  2016-10-17  View
47097  CVE-2012-6274  BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under AntServerDocDataPublic via unspecified vectors.    Medium  2017-01-19  2013-02-26  View
10283  CVE-2011-3711  BIGACE 2.7.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/libs/javascript.inc.php and certain other files.    Medium  2017-01-07  2012-03-13  View

Page 16136 of 17672, showing 5 records out of 88360 total, starting on record 80676, ending on 80680

Actions