NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 74449 | CVE-2003-1379 | clarkconnectd in ClarkConnect Linux 1.2 allows remote attackers to obtain sensitive information about the server via the characters (1) A, which reveals the date and time, (2) F, (3) M, which reveals "ifconfig" information, (4) P, which lists the processes, (5) Y, which reveals the snort log files, or (6) b, which reveals /var/log/messages. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
| 10288 | CVE-2011-3716 | Claroline 1.9.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by work/connector/linker.cnr.php and certain other files. | 2 | 5 | Medium | 2017-01-07 | 2012-03-13 | View | |
| 56859 | CVE-2007-4742 | Claroline before 1.8.6 allows remote authenticated administrators to obtain sensitive information via an invalid value in the sort parameter to admin/adminusers.php, which reveals the path in an error message in some circumstances, as demonstrated by a parameter value containing an XSS sequence. | 2 | 4.3 | Medium | 2017-01-07 | 2012-10-29 | View | |
| 59149 | CVE-2006-0411 | claro_init_local.inc.php in Claroline 1.7.2 uses guessable session cookies (MD5 hash of connection time), which allows remote attackers to hijack sessions and possibly gain administrative privileges. | 2 | 10 | High | 2016-12-20 | 2011-03-07 | View | |
| 80388 | CVE-2002-1435 | class.atkdateattribute.js.php in Achievo 0.7.0 through 0.9.1, except 0.8.2, allows remote attackers to execute arbitrary PHP code when the "allow_url_fopen" setting is enabled via a URL in the config_atkroot parameter that points to the code. | 2 | 7.5 | High | 2017-01-05 | 2008-09-05 | View |
Page 2584 of 17672, showing 5 records out of 88360 total, starting on record 12916, ending on 12920