NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
56274  CVE-2007-4143  user.php in the Billing Control Panel in phpCoupon allows remote authenticated users to obtain Premium Member status, and possibly acquire free coupons, via a modified URL containing a certain billing parameter and REQ=auth, status=success, and custom=upgrade substrings, possibly related to PayPal transactions.    Medium  2017-01-07  2008-09-05  View
43479  CVE-2012-1602  user.php in NextBBS 0.6 allows remote attackers to bypass authentication and gain administrator access by setting the userkey cookie to 1.    7.5  High  2017-01-19  2012-10-02  View
52846  CVE-2007-0624  user.php in MAXdev MDPro 1.0.76 allows remote attackers to obtain the full path via a " (quote) character, and possibly other invalid values, in the uname parameter in a userinfo operation.    Medium  2017-01-07  2008-11-13  View
68285  CVE-2005-2596  User.php in Gallery, as used in Postnuke, allows users with any Admin privileges to gain access to all galleries.    4.6  Medium  2017-01-03  2008-09-05  View
31505  CVE-2014-3302  user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCuj81708.    5.8  Medium  2017-01-19  2017-01-12  View

Page 668 of 17672, showing 5 records out of 88360 total, starting on record 3336, ending on 3340

Actions