NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
52425 | CVE-2007-0194 | admin.php in MKPortal M1.1 RC1 allows remote attackers to obtain sensitive information via a direct request with an MK_PATH=1 query string, which reveals the path in an error message. | 2 | 7.8 | High | 2017-01-07 | 2013-07-23 | View | |
49342 | CVE-2009-2080 | admin.php in MRCGIGUY The Ticket System 2.0 does not properly restrict access, which allows remote attackers to (1) obtain sensitive configuration information via the editconfig action or (2) change the administrator"s password via the id parameter in an editop action. | 2 | 7.5 | High | 2017-01-07 | 2009-06-17 | View | |
2214 | CVE-2008-2293 | admin.php in Multi-Page Comment System (MPCS) 1.0 and 1.1 allows remote attackers to bypass authentication and gain privileges by setting the CommentSystemAdmin cookie to 1. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
71048 | CVE-2004-0621 | admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the ulevel parameter set to 1 (administrator level), which lists all users and their passwords. | 2 | 10 | High | 2017-07-18 | 2017-07-10 | View | |
47900 | CVE-2009-0571 | admin.php in Ninja Designs Mailist 3.0 stores backup copies of maillist.php under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to the backup directory. | 2 | 5 | Medium | 2017-01-07 | 2009-02-17 | View |
Page 609 of 17672, showing 5 records out of 88360 total, starting on record 3041, ending on 3045