NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
52314 | CVE-2007-0082 | users_adm/start1.php in IMGallery 2.5 and earlier does not properly handle files with multiple extensions, which allows remote authenticated users to upload and execute arbitrary PHP scripts. | 2 | 6.5 | Medium | 2017-01-07 | 2011-03-07 | View | |
42051 | CVE-2013-7322 | usersfile.c in liboath in OATH Toolkit before 2.4.1 does not properly handle lines containing an invalid one-time-password (OTP) type and a user name in /etc/users.oath, which causes the wrong line to be updated when invalidating an OTP and allows context-dependent attackers to conduct replay attacks, as demonstrated by a commented out line when using libpam-oath. | 2 | 4.9 | Medium | 2017-01-18 | 2014-03-10 | View | |
61784 | CVE-2006-3104 | users/index.php in Bitweaver 1.3 allows remote attackers to obtain sensitive information via an invalid sort_mode parameter, which reveals the installation path and database information in the resultant error message. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
67307 | CVE-2005-1580 | users.ini.php in BoastMachine 3.0 does not properly restrict the types of files that can be uploaded, which allows remote attackers to execute arbitrary code. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
76769 | CVE-2000-0527 | userreg.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters. | 2 | 10 | High | 2017-01-05 | 2008-09-10 | View |
Page 662 of 17672, showing 5 records out of 88360 total, starting on record 3306, ending on 3310