NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
73529 | CVE-2003-0399 | Vignette StoryServer 4 and 5, Vignette V/5, and possibly other versions allows remote attackers to perform unauthorized SELECT queries by setting the vgn_creds cookie to an arbitrary value and directly accessing the save template. | 2 | 6.4 | Medium | 2017-01-03 | 2016-10-17 | View | |
73528 | CVE-2003-0398 | Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, with the SSI EXEC feature enabled, allows remote attackers to execute arbitrary code via a text variable to a Vignette Application that is later displayed. | 2 | 7.5 | High | 2017-01-03 | 2016-10-17 | View | |
79392 | CVE-2002-0385 | Vignette Story Server 4.1 and 6.0 allows remote attackers to obtain sensitive information via a request that contains a large number of '' (double quote) and and '>' characters, which causes the TCL interpreter to crash and include stack data in the output. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
45119 | CVE-2012-3527 | view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrary objects and possibly execute arbitrary PHP code via an unspecified parameter, related to a "missing signature (HMAC)." | 2 | 4.6 | Medium | 2017-01-19 | 2012-11-06 | View | |
61158 | CVE-2006-2463 | view_album.php in SelectaPix 1.31 and earlier allows remote attackers to obtain the installation path via a certain request, which displays the path in an error message, possibly due to an invalid or missing parameter. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 622 of 17672, showing 5 records out of 88360 total, starting on record 3106, ending on 3110