NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
55346 | CVE-2007-3192 | admin/setup.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to read and modify configuration settings via a direct request. | 2 | 9.4 | High | 2017-01-07 | 2012-10-30 | View | |
18429 | CVE-2016-2154 | admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to discover hidden course names by subscribing to a rule. | 2 | 4 | Medium | 2017-01-19 | 2016-05-24 | View | |
15604 | CVE-2010-4349 | admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to obtain sensitive information via an invalid db_type parameter, which reveals the installation path in an error message, related to an unsafe call by MantisBT to a function in the ADOdb Library for PHP. | 2 | 5 | Medium | 2017-01-18 | 2013-08-26 | View | |
59433 | CVE-2006-0702 | admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (dot dot) sequences in the path parameter. NOTE: due to the lack of details, the specific vulnerability type cannot be determined, although it might be due to directory traversal. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
2727 | CVE-2008-2833 | admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload and execute arbitrary files in images/, via a nonzero value for the submit0 parameter in conjunction with filenames in the filename and upload parameters. | 2 | 10 | High | 2017-01-03 | 2009-04-08 | View |
Page 629 of 17672, showing 5 records out of 88360 total, starting on record 3141, ending on 3145