NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
1808 | CVE-2008-1868 | admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote attackers to trigger a database backup dump, and obtain the resulting blogPM.sql file that contains sensitive information. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
51923 | CVE-2009-4806 | admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which allows remote attackers to read or modify the administrator"s credentials via unspecified vectors. NOTE: some of these details are obtained from third party information. | 2 | 7.5 | High | 2017-01-07 | 2010-04-26 | View | |
707 | CVE-2008-0736 | admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attackers to obtain the path via a certain value of the FedExAccount parameter. | 2 | 5 | Medium | 2017-01-03 | 2009-08-20 | View | |
54539 | CVE-2007-2372 | admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit when administrative credentials are missing, which allows remote attackers to compose an e-mail message via a post with the subject, message, format, and list_id fields; and send the message via a direct request for the MsgId value under admin/. | 2 | 10 | High | 2017-01-07 | 2008-09-05 | View | |
6266 | CVE-2008-6535 | admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the administrative password via a direct request with a modified NewAdmin parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-03-27 | View |
Page 628 of 17672, showing 5 records out of 88360 total, starting on record 3136, ending on 3140