NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86722 | CVE-2017-9548 | admin.php in BigTree through 4.2.18 has a Cross-site Scripting (XSS) vulnerability, which allows remote authenticated users to inject arbitrary web script or HTML by launching a Home Template Edit Page action and entering the Navigation Title of a page that is scheduled for future publication (aka a pending page change). | 2 | 3.5 | Low | 2017-06-17 | 2017-06-15 | View | |
86721 | CVE-2017-9547 | admin.php in BigTree through 4.2.18 has a Cross-site Scripting (XSS) vulnerability, which allows remote authenticated users to inject arbitrary web script or HTML by launching an Edit Page action and entering the Navigation Title or Page Title of a page that is scheduled for future publication (aka a pending page change). | 2 | 3.5 | Low | 2017-06-17 | 2017-06-15 | View | |
65557 | CVE-2006-7014 | admin.php in BloggIT 1.01 and earlier does not properly establish a user session, which allows remote attackers to gain privileges via a direct request. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
4909 | CVE-2008-5125 | admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin. | 2 | 6.8 | Medium | 2017-01-03 | 2009-01-29 | View | |
53052 | CVE-2007-0835 | admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to execute arbitrary shell commands via shell metacharacters (";" semicolon) in the "Command line options for ImageMagick" form field, when used as an option to ImageMagick"s convert command. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 6.5 | Medium | 2017-01-07 | 2008-11-15 | View |
Page 606 of 17672, showing 5 records out of 88360 total, starting on record 3026, ending on 3030