NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
61158 | CVE-2006-2463 | view_album.php in SelectaPix 1.31 and earlier allows remote attackers to obtain the installation path via a certain request, which displays the path in an error message, possibly due to an invalid or missing parameter. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
45119 | CVE-2012-3527 | view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrary objects and possibly execute arbitrary PHP code via an unspecified parameter, related to a "missing signature (HMAC)." | 2 | 4.6 | Medium | 2017-01-19 | 2012-11-06 | View | |
79392 | CVE-2002-0385 | Vignette Story Server 4.1 and 6.0 allows remote attackers to obtain sensitive information via a request that contains a large number of '' (double quote) and and '>' characters, which causes the TCL interpreter to crash and include stack data in the output. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
73528 | CVE-2003-0398 | Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, with the SSI EXEC feature enabled, allows remote attackers to execute arbitrary code via a text variable to a Vignette Application that is later displayed. | 2 | 7.5 | High | 2017-01-03 | 2016-10-17 | View | |
73529 | CVE-2003-0399 | Vignette StoryServer 4 and 5, Vignette V/5, and possibly other versions allows remote attackers to perform unauthorized SELECT queries by setting the vgn_creds cookie to an arbitrary value and directly accessing the save template. | 2 | 6.4 | Medium | 2017-01-03 | 2016-10-17 | View |
Page 17051 of 17672, showing 5 records out of 88360 total, starting on record 85251, ending on 85255