NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
35471  CVE-2014-8417  ConfBridge in Asterisk 11.x before 11.14.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified Asterisk 11.6 before 11.6-cert8 allows remote authenticated users to (1) gain privileges via vectors related to an external protocol to the CONFBRIDGE dialplan function or (2) execute arbitrary system commands via a crafted ConfbridgeStartRecord AMI action.    6.5  Medium  2017-01-19  2014-11-25  View
68619  CVE-2005-2955  config.inc.php in ATutor 1.5.1, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which allows authenticated administrators or educators to execute arbitrary code by uploading files with other executable extensions such as .inc, .php4, or others.    4.6  Medium  2017-01-03  2016-10-17  View
67853  CVE-2005-2149  config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.    10  High  2017-01-03  2011-03-07  View
60615  CVE-2006-1910  config.php in S9Y Serendipity 1.0 beta 2 allows remote attackers to inject arbitrary PHP code by editing values that are stored in config.php and later executed. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.    7.5  High  2016-12-20  2008-09-05  View
40985  CVE-2013-5755  config/.htpasswd in Yealink IP Phone SIP-T38G has a hardcoded password of (1) user (s7C9Cx.rLsWFA) for the user account, (2) admin (uoCbM.VEiKQto) for the admin account, and (3) var (jhl3iZAe./qXM) for the var account, which makes it easier for remote attackers to obtain access via unspecified vectors.    10  High  2017-01-18  2016-05-26  View

Page 2643 of 17672, showing 5 records out of 88360 total, starting on record 13211, ending on 13215

Actions