NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
74319 | CVE-2003-1249 | WebIntelligence 2.7.1 uses guessable user session cookies, which allows remote attackers to hijack sessions. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
10388 | CVE-2011-3816 | WEBinsta mailing list manager 1.3e allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by install/install3.php and certain other files. | 2 | 5 | Medium | 2017-01-07 | 2012-05-21 | View | |
2584 | CVE-2008-2686 | webinc/bxe/scripts/loadsave.php in Flux CMS 1.5.0 and earlier allows remote attackers to execute arbitrary code by overwriting a PHP file in webinc/bxe/scripts/ via a filename in the XML parameter and PHP sequences in the request body, then making a direct request for this filename. | 2 | 7.5 | High | 2017-01-03 | 2009-04-08 | View | |
78896 | CVE-2001-1462 | WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to cause the WebID agent to enter debug mode via a URL containing null characters, which may allow attackers to obtain sensitive information. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
6849 | CVE-2008-7118 | WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain SQL query logs via a direct request for logs/cron.log. | 2 | 5 | Medium | 2017-01-03 | 2009-08-28 | View |
Page 414 of 17672, showing 5 records out of 88360 total, starting on record 2066, ending on 2070