NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
138  CVE-2008-0148  TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell commands via the cmd parameter in a direct request.    10  High  2017-01-03  2008-09-05  View
139  CVE-2008-0149  TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls the phpinfo function.    Medium  2017-01-03  2008-09-05  View
73609  CVE-2003-0482  TUTOS 1.1 allows remote attackers to execute arbitrary code by uploading the code using file_new.php, then directly accessing the uploaded code via a request to the repository containing the code.    7.5  High  2017-01-03  2016-10-17  View
54985  CVE-2007-2822  TutorialCMS 1.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication via the (1) loggedIn and (2) activated parameters to (a) login.php, (b) headerLinks.php, (c) submit1.php, (d) myFav.php, and (e) userCP.php.    9.3  High  2017-01-07  2011-03-07  View
6671  CVE-2008-6940  TurnkeyForms Web Hosting Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain a database backup via a direct request to admin/backup/db.    7.5  High  2017-01-03  2009-08-12  View

Page 2449 of 17672, showing 5 records out of 88360 total, starting on record 12241, ending on 12245

Actions