NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
22717  CVE-2015-0216  access.php in the Lesson module in Moodle 2.8.x before 2.8.2 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted essay feedback.    3.5  Low  2017-01-19  2015-06-02  View
46635  CVE-2012-5507  AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation.    4.3  Medium  2017-01-19  2014-10-02  View
13748  CVE-2010-2270  Accoria Web Server (aka Rock Web Server) 1.4.7 uses a predictable httpmod-sessionid cookie, which makes it easier for remote attackers to hijack sessions via a modified cookie.    7.5  High  2017-01-18  2010-06-17  View
76930  CVE-2000-0689  Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the amadmin.pl script with the setpasswd parameter.    7.5  High  2017-07-18  2017-07-10  View
49420  CVE-2009-2158  account-recover.php in TorrentTrader Classic 1.09 chooses random passwords from an insufficiently large set, which makes it easier for remote attackers to obtain a password via a brute-force attack.    7.5  High  2017-01-07  2009-06-25  View

Page 576 of 17672, showing 5 records out of 88360 total, starting on record 2876, ending on 2880

Actions