NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
52540 | CVE-2007-0312 | wcSimple Poll stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password hashes via a direct request for password.txt. | 2 | 7.8 | High | 2017-01-07 | 2008-11-15 | View | |
5687 | CVE-2008-5956 | Wbstreet (aka PHPSTREET Webboard) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request to connect.inc. | 2 | 5 | Medium | 2017-01-03 | 2009-05-14 | View | |
5550 | CVE-2008-5810 | WBPublish (aka WBPublish.exe) in Fujitsu-Siemens WebTransactions 7.0, 7.1, and possibly other versions allows remote attackers to execute arbitrary commands via shell metacharacters in input that is sent through HTTP and improperly used during temporary session data cleanup, possibly related to (1) directory names, (2) template names, and (3) session IDs. | 2 | 10 | High | 2017-01-03 | 2011-03-07 | View | |
52042 | CVE-2009-4927 | WB News 2.1.2 allows remote attackers to bypass authentication and gain administrative access via a modified WBNEWS cookie, as demonstrated by setting this cookie to 1. | 2 | 7.5 | High | 2017-01-07 | 2010-07-16 | View | |
77692 | CVE-2001-0214 | Way-board CGI program allows remote attackers to read arbitrary files by specifying the filename in the db parameter and terminating the filename with a null byte. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View |
Page 437 of 17672, showing 5 records out of 88360 total, starting on record 2181, ending on 2185