NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
1808  CVE-2008-1868  admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote attackers to trigger a database backup dump, and obtain the resulting blogPM.sql file that contains sensitive information.    7.5  High  2017-01-03  2011-03-07  View
51923  CVE-2009-4806  admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which allows remote attackers to read or modify the administrator"s credentials via unspecified vectors. NOTE: some of these details are obtained from third party information.    7.5  High  2017-01-07  2010-04-26  View
707  CVE-2008-0736  admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attackers to obtain the path via a certain value of the FedExAccount parameter.    Medium  2017-01-03  2009-08-20  View
54539  CVE-2007-2372  admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit when administrative credentials are missing, which allows remote attackers to compose an e-mail message via a post with the subject, message, format, and list_id fields; and send the message via a direct request for the MsgId value under admin/.    10  High  2017-01-07  2008-09-05  View
6266  CVE-2008-6535  admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the administrative password via a direct request with a modified NewAdmin parameter.    7.5  High  2017-01-03  2009-03-27  View

Page 628 of 17672, showing 5 records out of 88360 total, starting on record 3136, ending on 3140

Actions