NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
78733 | CVE-2001-1298 | Webodex PHP script 1.0 and earlier allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. | 2 | 5 | Medium | 2017-01-05 | 2008-09-10 | View | |
44703 | CVE-2012-3030 | WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, stores sensitive information under the web root with insufficient access control, which allows remote attackers to read a (1) log file or (2) configuration file via a direct request. | 2 | 5 | Medium | 2017-01-19 | 2012-12-20 | View | |
44706 | CVE-2012-3034 | WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to discover a username and password via crafted parameters to unspecified methods in ActiveX controls. | 2 | 4.3 | Medium | 2017-01-19 | 2012-09-19 | View | |
63175 | CVE-2006-4542 | Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-09 | View | |
62070 | CVE-2006-3392 | Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename. NOTE: This is a different issue than CVE-2006-3274. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 275 of 17672, showing 5 records out of 88360 total, starting on record 1371, ending on 1375