NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 57087 | CVE-2007-4998 | cp, when running with an option to preserve symlinks on multiple OSes, allows local, user-assisted attackers to overwrite arbitrary files via a symlink attack using crafted directories containing multiple source files that are copied to the same destination. | 2 | 6.9 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 58240 | CVE-2007-6237 | cp.php in DeluxeBB 1.09 does not verify that the membercookie parameter corresponds to the authenticated member during a profile update, which allows remote authenticated users to change the e-mail addresses of arbitrary accounts via a modified membercookie parameter, a different vector than CVE-2006-4078. NOTE: this can be leveraged for administrative access by requesting password-reset e-mail through a lostpw action to misc.php. | 2 | 9 | High | 2017-01-07 | 2008-09-05 | View | |
| 51108 | CVE-2009-3949 | cp/profile.php in VivaPrograms Infinity 2.0.5 and earlier does not require administrative authentication for the donewauthor action, which allows remote attackers to create administrative accounts via the name, password, and conf_password parameters. | 2 | 7.5 | High | 2017-01-07 | 2009-11-18 | View | |
| 1228 | CVE-2008-1269 | cp06_wifi_m_nocifr.cgi in the admin panel on the Alice Gate 2 Plus Wi-Fi router does not verify authentication credentials, which allows remote attackers to disable Wi-Fi encryption via a certain request. | 2 | 7.1 | High | 2017-01-03 | 2008-09-05 | View | |
| 71982 | CVE-2004-1603 | cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 2687 of 17672, showing 5 records out of 88360 total, starting on record 13431, ending on 13435