NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
1806  CVE-2008-1866  admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to upload arbitrary PHP scripts in a ZIP archive, which is written to templateZip/ and then automatically extracted under templates/ for execution via a direct request.    High  2017-01-03  2011-03-07  View
64561  CVE-2006-5986  admin/options.php in Extreme CMS 0.9, and possibly earlier, does not require authentication, which might allow remote attackers to conduct unauthorized activities. NOTE: this issue can be combined with another vulnerability to expand the scope of a cross-site scripting (XSS) attack without authentication. NOTE: the provenance of this information is unknown; details are obtained from third party sources.    6.8  Medium  2016-12-20  2011-03-07  View
49302  CVE-2009-2040  admin/options.php in Grestul 1.2 does not properly restrict access, which allows remote attackers to bypass authentication and create administrative accounts via a manage_admin action in a direct request.    7.5  High  2017-01-07  2009-06-15  View
54317  CVE-2007-2147  admin/options.php in Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier does not check for administrative credentials, which allows remote attackers to read and modify the classes/vars.php and classes/varstuff.php configuration files via direct requests.    10  High  2017-01-07  2011-03-07  View
32874  CVE-2014-5090  admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the Location field in Add Logs in the Admin Panel.    6.5  Medium  2017-01-19  2014-08-07  View

Page 626 of 17672, showing 5 records out of 88360 total, starting on record 3126, ending on 3130

Actions