NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
1806 | CVE-2008-1866 | admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to upload arbitrary PHP scripts in a ZIP archive, which is written to templateZip/ and then automatically extracted under templates/ for execution via a direct request. | 2 | 9 | High | 2017-01-03 | 2011-03-07 | View | |
64561 | CVE-2006-5986 | admin/options.php in Extreme CMS 0.9, and possibly earlier, does not require authentication, which might allow remote attackers to conduct unauthorized activities. NOTE: this issue can be combined with another vulnerability to expand the scope of a cross-site scripting (XSS) attack without authentication. NOTE: the provenance of this information is unknown; details are obtained from third party sources. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
49302 | CVE-2009-2040 | admin/options.php in Grestul 1.2 does not properly restrict access, which allows remote attackers to bypass authentication and create administrative accounts via a manage_admin action in a direct request. | 2 | 7.5 | High | 2017-01-07 | 2009-06-15 | View | |
54317 | CVE-2007-2147 | admin/options.php in Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier does not check for administrative credentials, which allows remote attackers to read and modify the classes/vars.php and classes/varstuff.php configuration files via direct requests. | 2 | 10 | High | 2017-01-07 | 2011-03-07 | View | |
32874 | CVE-2014-5090 | admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the Location field in Add Logs in the Admin Panel. | 2 | 6.5 | Medium | 2017-01-19 | 2014-08-07 | View |
Page 626 of 17672, showing 5 records out of 88360 total, starting on record 3126, ending on 3130