NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 11843 | CVE-2010-0275 | Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properly handle script commands in the status-alerts URL, which has unspecified impact and attack vectors, aka SPR LSHR7TBM58. | 2 | 10 | High | 2017-01-18 | 2010-03-26 | View | |
| 67739 | CVE-2005-2030 | Ultimate PHP Board (UPB) 1.9.6 GOLD uses weak encryption for passwords in the users.dat file, which allows attackers to easily decrypt the passwords and gain privileges, possibly after exploiting CVE-2005-2005 to obtain users.dat. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View | |
| 67717 | CVE-2005-2005 | Ultimate PHP Board (UPB) 1.9.6 GOLD and earlier stores the users.dat file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information on registered users via a direct request to db/users.dat. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View | |
| 67715 | CVE-2005-2003 | Ultimate PHP Board (UPB) 1.9.6 GOLD allows remote attackers to obtain sensitive information via an invalid (zero) id parameter to (1) viewtopic.php, (2) profile.php, or (3) newpost.php, which reveals the path in an error message. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View | |
| 61883 | CVE-2006-3204 | Ultimate PHP Board (UPB) 1.9.6 and earlier uses a cryptographically weak block cipher with a large key collision space, which allows remote attackers to determine a suitable decryption key given the plaintext and ciphertext by obtaining the plaintext password, which is sent when logging in, and the ciphertext, which is set in the pass_env cookie. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 2430 of 17672, showing 5 records out of 88360 total, starting on record 12146, ending on 12150