NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
53655 | CVE-2007-1471 | admin/default.asp in Orion-Blog 2.0 allows remote attackers to bypass authentication controls and gain privileges via a direct URL request for admin/AdminBlogNewsEdit.asp. | 2 | 7.5 | High | 2017-01-07 | 2008-11-13 | View | |
61273 | CVE-2006-2578 | admin/cron.php in eSyndicat Directory 1.2, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include arbitrary files and possibly execute arbitrary PHP code via a null-terminated value in the path_to_config parameter. | 2 | 5.1 | Medium | 2016-12-20 | 2011-03-07 | View | |
46994 | CVE-2012-6038 | admin/core/admin_func.php in razorCMS before 1.2.1 does not properly restrict access to certain administrator directories and files, which allows remote authenticated users to read, edit, rename, move, copy and delete files via the (1) dir parameter in a fileman or (2) filemanview action. NOTE: this issue has been referred to as a "path traversal." | 2 | 6.5 | Medium | 2017-01-19 | 2012-11-27 | View | |
53787 | CVE-2007-1603 | admin/contest.php in Weekly Drawing Contest 0.0.1 allows remote attackers to bypass authentication, and insert new contest information into a database, via a direct POST request. | 2 | 7.5 | High | 2017-01-07 | 2008-09-05 | View | |
41708 | CVE-2013-6829 | admin/confnetworking.html in PineApp Mail-SeCure allows remote attackers to execute arbitrary commands via shell metacharacters in the pinghost parameter during a ping operation. | 2 | 7.5 | High | 2017-01-18 | 2013-11-21 | View |
Page 17055 of 17672, showing 5 records out of 88360 total, starting on record 85271, ending on 85275