NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 7998 | CVE-2011-1008 | Scrips_Overlay.pm in Best Practical Solutions RT before 3.8.9 does not properly restrict access to a TicketObj in a Scrip after a CurrentUser change, which allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by custom-field value information, related to SQL logging. | 2 | 4 | Medium | 2017-01-07 | 2011-03-10 | View | |
| 25150 | CVE-2015-3273 | mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization. | 2 | 4 | Medium | 2017-01-19 | 2016-03-01 | View | |
| 38462 | CVE-2013-2399 | Unspecified vulnerability in the Siebel Call Center component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via vectors related to Email - COMM Server Components. | 2 | 4 | Medium | 2017-01-18 | 2013-10-10 | View | |
| 62014 | CVE-2006-3336 | TWiki 01-Dec-2000 up to 4.0.3 allows remote attackers to bypass the upload filter and execute arbitrary code via filenames with double extensions such as ".php.en", ".php.1", and other allowed extensions that are not .txt. NOTE: this is only a vulnerability when the server allows script execution in the pub directory. | 2 | 4 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 62526 | CVE-2006-3859 | IBM Informix Dynamic Server (IDS) allows remote authenticated users to create and overwrite arbitrary files via the (1) LOTOFILE and (2) trl_tracefile_set functions, and the (3) "SET DEBUG FILE" commands. | 2 | 4 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 3020 of 17672, showing 5 records out of 88360 total, starting on record 15096, ending on 15100