NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86722  CVE-2017-9548  admin.php in BigTree through 4.2.18 has a Cross-site Scripting (XSS) vulnerability, which allows remote authenticated users to inject arbitrary web script or HTML by launching a Home Template Edit Page action and entering the Navigation Title of a page that is scheduled for future publication (aka a pending page change).    3.5  Low  2017-06-17  2017-06-15  View
86721  CVE-2017-9547  admin.php in BigTree through 4.2.18 has a Cross-site Scripting (XSS) vulnerability, which allows remote authenticated users to inject arbitrary web script or HTML by launching an Edit Page action and entering the Navigation Title or Page Title of a page that is scheduled for future publication (aka a pending page change).    3.5  Low  2017-06-17  2017-06-15  View
65557  CVE-2006-7014  admin.php in BloggIT 1.01 and earlier does not properly establish a user session, which allows remote attackers to gain privileges via a direct request.    7.5  High  2016-12-20  2011-03-07  View
4909  CVE-2008-5125  admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin.    6.8  Medium  2017-01-03  2009-01-29  View
53052  CVE-2007-0835  admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to execute arbitrary shell commands via shell metacharacters (";" semicolon) in the "Command line options for ImageMagick" form field, when used as an option to ImageMagick"s convert command. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.    6.5  Medium  2017-01-07  2008-11-15  View

Page 606 of 17672, showing 5 records out of 88360 total, starting on record 3026, ending on 3030

Actions