NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
5698  CVE-2008-5967  admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.    7.5  High  2017-01-03  2009-02-05  View
5523  CVE-2008-5783  admin/index.php in V3 Chat Live Support 3.0.4 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1.    7.5  High  2017-01-03  2011-03-07  View
49640  CVE-2009-2393  admin/index.php in Virtuenetz Virtue Online Test Generator does not require administrative privileges, which allows remote authenticated users to have an unknown impact via unspecified vectors.    6.5  Medium  2017-01-07  2009-07-09  View
17441  CVE-2016-10085  admin/languages.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the tab parameter.    6.5  Medium  2017-01-19  2017-01-03  View
30439  CVE-2014-1903  admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not restrict the set of functions accessible to the API handler, which allows remote attackers to execute arbitrary PHP code via the function and args parameters to admin/config.php.    7.5  High  2017-02-28  2017-02-23  View

Page 624 of 17672, showing 5 records out of 88360 total, starting on record 3116, ending on 3120

Actions