NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84976 | CVE-2017-7881 | BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the required admin/developer/ URI within a query string in an HTTP Referer header. This was found in core/admin/modules/developer/_header.php and patched in core/inc/bigtree/admin.php on 2017-04-14. | 2 | 6.8 | Medium | 2017-04-27 | 2017-04-21 | View | |
79468 | CVE-2002-0462 | bigsam_guestbook.php for Big Sam (Built-In Guestbook Stand-Alone Module) 1.1.08 and earlier allows remote attackers to cause a denial of service (CPU consumption) or obtain the absolute path of the web server via a displayBegin parameter with a very large number, which leaks the web path in an error message when PHP safe_mode is enabled, or consumes resources when safe_mode is not enabled. | 2 | 6.4 | Medium | 2017-01-05 | 2008-09-05 | View | |
76200 | CVE-1999-1550 | bigconf.conf in F5 BIG/ip 2.1.2 and earlier allows remote attackers to read arbitrary files by specifying the target file in the "file" parameter. | 2 | 5 | Medium | 2017-01-05 | 2016-10-17 | View | |
47097 | CVE-2012-6274 | BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under AntServerDocDataPublic via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2013-02-26 | View | |
10283 | CVE-2011-3711 | BIGACE 2.7.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/libs/javascript.inc.php and certain other files. | 2 | 5 | Medium | 2017-01-07 | 2012-03-13 | View |
Page 16136 of 17672, showing 5 records out of 88360 total, starting on record 80676, ending on 80680