NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
55103  CVE-2007-2944  WabCMS 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/wabcmsn.mdb. NOTE: this issue was originally reported for "webCMS," but this was an error by an unreliable researcher.    Medium  2017-01-07  2008-11-15  View
81282  CVE-2002-2331  W3Mail 1.0.2 through 1.0.5 with server side scripting (SSI) enabled in the attachments directory does not properly restrict the types of files that can be uploaded as attachments, which allows remote attackers to execute arbitrary code by sending code in MIME attachments, then requesting the attachments.    5.8  Medium  2017-01-05  2008-09-05  View
80301  CVE-2002-1348  w3m before 0.3.2.2 does not properly escape HTML tags in the ALT attribute of an IMG tag, which could allow remote attackers to access files or cookies.    Medium  2017-01-05  2016-10-17  View
52828  CVE-2007-0606  w-agora 4.2.1 allows remote attackers to obtain sensitive information by via the (1) bn[] array parameter to index.php, which expects a string, and (2) certain parameters to delete_forum.php, which displays the path name in the resulting error message.    Medium  2017-01-07  2008-09-05  View
53789  CVE-2007-1605  w-Agora (Web-Agora) allows remote attackers to obtain sensitive information via a request to rss.php with an invalid (1) site or (2) bn parameter, (3) a certain value of the site[] parameter, or (4) an empty value of the bn[] parameter; a request to index.php with a certain value of the (5) site[] or (6) sort[] parameter; (7) a request to profile.php with an empty value of the site[] parameter; or a request to search.php with (8) an empty value of the bn[] parameter or a certain value of the (9) pattern[] or (10) search_date[] parameter, which reveal the path in various error messages, probably related to variable type inconsistencies. NOTE: the bn[] parameter to index.php is already covered by CVE-2007-0606.1.    Medium  2017-01-07  2008-11-13  View

Page 444 of 17672, showing 5 records out of 88360 total, starting on record 2216, ending on 2220

Actions