NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 42871 | CVE-2012-0796 | class.phpmailer.php in the PHPMailer library, as used in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 and other products, allows remote authenticated users to inject arbitrary e-mail headers via vectors involving a crafted (1) From: or (2) Sender: header. | 2 | 4 | Medium | 2017-01-19 | 2012-07-17 | View | |
| 72953 | CVE-2004-2576 | class.vfs_dav.inc.php in phpGroupWare 0.9.16.000 does not create .htaccess files to enable authorization checks for access to users' home-directory files, which allows remote attackers to obtain sensitive information from these files. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 67885 | CVE-2005-2183 | class.xmail.php in PhpXmail 0.7 through 1.1 does not properly handle large passwords, which prevents an error message from being returned and allows remote attackers to bypass authentication and gain unauthorized access. | 2 | 7.5 | High | 2017-01-03 | 2016-10-17 | View | |
| 55801 | CVE-2007-3651 | class/page.php in Farsi Script (aka FaScript) FaName 1.0 allows remote attackers to obtain sensitive information via a "; (quote semicolon) sequence in the id parameter, which reveals the installation path in an error message. | 2 | 4.3 | Medium | 2017-01-07 | 2008-09-05 | View | |
| 27698 | CVE-2015-6928 | classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a password reset request was made, which allows remote attackers to change the administrator password via a recovery request with a space character in the validate parameter and the administrator email in the email parameter. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-07 | View |
Page 2585 of 17672, showing 5 records out of 88360 total, starting on record 12921, ending on 12925