NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 59574 | CVE-2006-0844 | Leif M. Wright"s Blog 3.5 does not make a password comparison when authenticating an administrator via a cookie, which allows remote attackers to bypass login authentication, probably by setting the blogAdmin cookie. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
| 59575 | CVE-2006-0845 | Leif M. Wright"s Blog 3.5 allows remote authenticated users with administrative privileges to execute arbitrary programs, including shell commands, by configuring the sendmail path to a malicious pathname. | 2 | 6.5 | Medium | 2016-12-20 | 2008-09-05 | View | |
| 59576 | CVE-2006-0846 | Multiple cross-site scripting (XSS) vulnerabilities in Leif M. Wright"s Blog 3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Referer and (2) User-Agent HTTP headers, which are stored in a log file and not sanitized when the administrator views the "Log" page, possibly using the ViewCommentsLog function. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
| 59577 | CVE-2006-0847 | Directory traversal vulnerability in the staticfilter component in CherryPy before 2.1.1 allows remote attackers to read arbitrary files via ".." sequences in unspecified vectors. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 59578 | CVE-2006-0848 | The "Open "safe" files after downloading" option in Safari on Apple Mac OS X allows remote user-assisted attackers to execute arbitrary commands by tricking a user into downloading a __MACOSX folder that contains metadata (resource fork) that invokes the Terminal, which automatically interprets the script using bash, as demonstrated using a ZIP file that contains a script with a safe file extension. | 2 | 5.1 | Medium | 2016-12-20 | 2013-08-18 | View |
Page 3286 of 17672, showing 5 records out of 88360 total, starting on record 16426, ending on 16430