NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5698 | CVE-2008-5967 | admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root. | 2 | 7.5 | High | 2017-01-03 | 2009-02-05 | View | |
5523 | CVE-2008-5783 | admin/index.php in V3 Chat Live Support 3.0.4 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
49640 | CVE-2009-2393 | admin/index.php in Virtuenetz Virtue Online Test Generator does not require administrative privileges, which allows remote authenticated users to have an unknown impact via unspecified vectors. | 2 | 6.5 | Medium | 2017-01-07 | 2009-07-09 | View | |
17441 | CVE-2016-10085 | admin/languages.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the tab parameter. | 2 | 6.5 | Medium | 2017-01-19 | 2017-01-03 | View | |
30439 | CVE-2014-1903 | admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not restrict the set of functions accessible to the API handler, which allows remote attackers to execute arbitrary PHP code via the function and args parameters to admin/config.php. | 2 | 7.5 | High | 2017-02-28 | 2017-02-23 | View |
Page 624 of 17672, showing 5 records out of 88360 total, starting on record 3116, ending on 3120