NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
79584  CVE-2002-0579  WorkforceROI Xpede 4.1 allows remote attackers to gain privileges as an Xpede administrator via a direct HTTP request to the /admin/adminproc.asp script, which does not prompt for a password.    7.5  High  2017-01-05  2008-09-05  View
79586  CVE-2002-0581  WorkforceROI Xpede 4.1 allows remote attackers to execute arbitrary SQL commands and read, modify, or steal credentials from the database via the Qry parameter in the sprc.asp script.    7.5  High  2017-01-05  2008-09-05  View
74530  CVE-2003-1460  Worker Filemanager 1.0 through 2.7 sets the permissions on the destination directory to world-readable and executable while copying data, which could allow local users to obtain sensitive information.    3.6  Low  2017-01-03  2008-09-05  View
79836  CVE-2002-0837  wordtrans 1.1pre8 and earlier in the wordtrans-web package allows remote attackers to (1) execute arbitrary code or (2) conduct cross-site scripting attacks via certain parameters (possibly "dict") to the wordtrans.php script.    7.5  High  2017-01-05  2016-10-17  View
85510  CVE-2017-8295  WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbitrary passwords by making a crafted wp-login.php?action=lostpassword request and then arranging for this message to bounce or be resent, leading to transmission of the reset key to a mailbox on an attacker-controlled SMTP server. This is related to problematic use of the SERVER_NAME variable in wp-includes/pluggable.php in conjunction with the PHP mail function. Exploitation is not achievable in all cases because it requires at least one of the following: (1) the attacker can prevent the victim from receiving any e-mail messages for an extended period of time (such as 5 days), (2) the victim's e-mail system sends an autoresponse containing the original message, or (3) the victim manually composes a reply containing the original message.    4.3  Medium  2017-07-18  2017-07-17  View

Page 162 of 17672, showing 5 records out of 88360 total, starting on record 806, ending on 810

Actions