NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
22717 | CVE-2015-0216 | access.php in the Lesson module in Moodle 2.8.x before 2.8.2 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted essay feedback. | 2 | 3.5 | Low | 2017-01-19 | 2015-06-02 | View | |
46635 | CVE-2012-5507 | AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation. | 2 | 4.3 | Medium | 2017-01-19 | 2014-10-02 | View | |
13748 | CVE-2010-2270 | Accoria Web Server (aka Rock Web Server) 1.4.7 uses a predictable httpmod-sessionid cookie, which makes it easier for remote attackers to hijack sessions via a modified cookie. | 2 | 7.5 | High | 2017-01-18 | 2010-06-17 | View | |
76930 | CVE-2000-0689 | Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the amadmin.pl script with the setpasswd parameter. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
49420 | CVE-2009-2158 | account-recover.php in TorrentTrader Classic 1.09 chooses random passwords from an insufficiently large set, which makes it easier for remote attackers to obtain a password via a brute-force attack. | 2 | 7.5 | High | 2017-01-07 | 2009-06-25 | View |
Page 576 of 17672, showing 5 records out of 88360 total, starting on record 2876, ending on 2880