NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49580  CVE-2009-2332  CMS Chainuk 1.2 and earlier allows remote attackers to obtain sensitive information via (1) a crafted id parameter to index.php or (2) a nonexistent folder name in the id parameter to admin/admin_delete.php, which reveals the installation path in an error message.    Medium  2017-01-07  2009-07-16  View
10290  CVE-2011-3718  CMS Made Simple (CMSMS) 1.9.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/TinyMCE/TinyMCE.module.php and certain other files. NOTE: this might overlap CVE-2007-5444.    Medium  2017-01-07  2012-03-13  View
57509  CVE-2007-5444  CMS Made Simple 1.1.3.1 allows remote attackers to obtain the full path via a direct request for unspecified files.    Medium  2017-01-07  2008-11-15  View
57506  CVE-2007-5441  CMS Made Simple 1.1.3.1 does not check the permissions assigned to users in some situations, which allows remote authenticated users to perform some administrative actions, as demonstrated by (1) adding a user via a direct request to admin/adduser.php and (2) reading the admin log via an "admin/adminlog.php?page=1" request.    6.5  Medium  2017-01-07  2008-11-15  View
57507  CVE-2007-5442  CMS Made Simple 1.1.3.1 does not check the permissions assigned to users who attempt uploads, which allows remote authenticated users to upload unspecified files via unknown vectors.    3.5  Low  2017-01-07  2008-09-05  View

Page 2602 of 17672, showing 5 records out of 88360 total, starting on record 13006, ending on 13010

Actions