NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
5005  CVE-2008-5221  The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified password and password_retype parameters.    7.5  High  2017-01-03  2011-03-07  View
5004  CVE-2008-5220  Unrestricted file upload vulnerability in admin/upload_form.php in wPortfolio 0.3 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in admin/tmp/.    10  High  2017-01-03  2011-03-07  View
5003  CVE-2008-5219  The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified npass and npass1 parameters.    7.5  High  2017-01-03  2009-01-29  View
5002  CVE-2008-5218  ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain cleartext passwords.    Medium  2017-01-03  2009-08-13  View
5001  CVE-2008-5217  Directory traversal vulnerability in index.php in txtCMS 0.3, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter.    5.1  Medium  2017-01-03  2009-04-17  View

Page 16672 of 17672, showing 5 records out of 88360 total, starting on record 83356, ending on 83360

Actions