NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
385 | CVE-2008-0407 | HTTP File Server (HFS) before 2.2c tags HTTP request log entries with the username sent during HTTP Basic Authentication, regardless of whether authentication succeeded, which might make it more difficult for an administrator to determine who made a remote request. | 2 | 5 | Medium | 2017-01-03 | 2009-09-16 | View | |
384 | CVE-2008-0406 | HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allows remote attackers to cause a denial of service (daemon crash) via a long account name. | 2 | 5 | Medium | 2017-01-03 | 2009-09-16 | View | |
383 | CVE-2008-0405 | Multiple directory traversal vulnerabilities in HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allow remote attackers to create arbitrary (1) files and (2) directories via a .. (dot dot) in an account name, when requesting the / URI; and (3) append arbitrary data to a file via a .. (dot dot) in an account name, when requesting a URI composed of a "/?%0a" sequence followed by the data. | 2 | 10 | High | 2017-01-03 | 2009-09-16 | View | |
382 | CVE-2008-0404 | Cross-site scripting (XSS) vulnerability in Mantis before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "Most active bugs" summary. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View | |
381 | CVE-2008-0403 | The web server in Belkin Wireless G Plus MIMO Router F5D9230-4 does not require authentication for SaveCfgFile.cgi, which allows remote attackers to read and modify configuration via a direct request to SaveCfgFile.cgi. | 2 | 5.5 | Medium | 2017-01-03 | 2011-03-07 | View |
Page 17596 of 17672, showing 5 records out of 88360 total, starting on record 87976, ending on 87980