NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
1866  CVE-2008-1930  The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as demonstrated by registering usernames beginning with "admin" to obtain administrator privileges, aka a "cryptographic splicing" issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-6013.    7.5  High  2017-01-03  2011-03-07  View
67402  CVE-2005-1677  Unknown vulnerability in Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 allows remote attackers to bypass restrictions on COM objects.    7.5  High  2017-01-03  2008-09-05  View
67658  CVE-2005-1943  Multiple SQL injection vulnerabilities in Loki download manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) password field to default.asp or (2) cat parameter to catinfo.asp.    7.5  High  2017-01-03  2016-10-17  View
70218  CVE-2005-4629  SQL injection vulnerability in SMBCMS 2.1 allows remote attackers to execute arbitrary SQL commands via unspecified search parameters.    7.5  High  2017-01-03  2008-09-20  View
70474  CVE-2005-4885  Unspecified vulnerability on certain Sun StorEdge 6130 (SE6130) Controller Arrays allows remote attackers to delete data via unknown vectors.    7.5  High  2017-01-03  2010-01-31  View

Page 2768 of 17672, showing 5 records out of 88360 total, starting on record 13836, ending on 13840

Actions