NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
4491  CVE-2008-4677  autoload/netrw.vim (aka the Netrw Plugin) 109, 131, and other versions before 133k for Vim 7.1.266, other 7.1 versions, and 7.2 stores credentials for an FTP session, and sends those credentials when attempting to establish subsequent FTP sessions to servers on different hosts, which allows remote FTP servers to obtain sensitive information in opportunistic circumstances by logging usernames and passwords. NOTE: the upstream vendor disputes a vector involving different ports on the same host, stating "I"m assuming that they"re using the same id and password on that unchanged hostname, deliberately."    4.3  Medium  2017-01-03  2009-04-01  View
70027  CVE-2005-4429  SQL injection vulnerability in CS-Cart 1.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) sort_by and (2) sort_order parameters to index.php.    7.5  High  2017-01-03  2008-09-20  View
4747  CVE-2008-4958  gdrae in gdrae 0.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gdrae/palabra temporary file.    6.9  Medium  2017-01-03  2009-08-26  View
70283  CVE-2005-4694  Unspecified vulnerability in the www_add method in Asset.pm in Plain Black WebGUI 6.3.0 and other versions before 6.7.6 allows attackers to execute arbitrary code via unknown attack vectors.    7.5  High  2017-01-03  2011-03-07  View
5003  CVE-2008-5219  The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified npass and npass1 parameters.    7.5  High  2017-01-03  2009-01-29  View

Page 2783 of 17672, showing 5 records out of 88360 total, starting on record 13911, ending on 13915

Actions