NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
60327  CVE-2006-1620  admin/accounts/AccountActions.asp in Hosting Controller 2002 RC 1 allows remote attackers to modify passwords of other users, probably via an "Update User" ActionType with a modified UserName parameter and the PassCheck parameter set to TRUE. It was later reported that the vulnerability is present in 6.1 Hotfix 3.3 and earlier.    Medium  2016-12-20  2008-09-05  View
51791  CVE-2009-4674  admin/admin.php in Mole Group Sky Hunter Airline Ticket Sale Script and Bus Ticket Script allows remote attackers to change an arbitrary password via a modified user_id field.    7.5  High  2017-01-07  2010-03-05  View
61222  CVE-2006-2527  Admin/admin.php in phpBazar 2.1.0 and earlier allows remote attackers to bypass the authentication process and gain unauthorized access to the administrative section by setting the action parameter to edit_member and the value parameter to 1.    7.5  High  2016-12-20  2011-03-07  View
48921  CVE-2009-1652  admin/adminaddeditdetails.php in Business Community Script does not properly restrict access, which allows remote attackers to gain privileges and add administrators via a direct request.    7.5  High  2017-01-07  2009-05-23  View
58409  CVE-2007-6414  admin/administrator.php in Adult Script 1.6 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to bypass authentication and obtain administrative credentials via a direct request. NOTE: this can be leveraged for arbitrary code execution through a request to admin/videolinks_view.php.    7.5  High  2017-01-07  2008-09-05  View

Page 614 of 17672, showing 5 records out of 88360 total, starting on record 3066, ending on 3070

Actions