NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
56274 | CVE-2007-4143 | user.php in the Billing Control Panel in phpCoupon allows remote authenticated users to obtain Premium Member status, and possibly acquire free coupons, via a modified URL containing a certain billing parameter and REQ=auth, status=success, and custom=upgrade substrings, possibly related to PayPal transactions. | 2 | 4 | Medium | 2017-01-07 | 2008-09-05 | View | |
43479 | CVE-2012-1602 | user.php in NextBBS 0.6 allows remote attackers to bypass authentication and gain administrator access by setting the userkey cookie to 1. | 2 | 7.5 | High | 2017-01-19 | 2012-10-02 | View | |
52846 | CVE-2007-0624 | user.php in MAXdev MDPro 1.0.76 allows remote attackers to obtain the full path via a " (quote) character, and possibly other invalid values, in the uname parameter in a userinfo operation. | 2 | 5 | Medium | 2017-01-07 | 2008-11-13 | View | |
68285 | CVE-2005-2596 | User.php in Gallery, as used in Postnuke, allows users with any Admin privileges to gain access to all galleries. | 2 | 4.6 | Medium | 2017-01-03 | 2008-09-05 | View | |
31505 | CVE-2014-3302 | user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCuj81708. | 2 | 5.8 | Medium | 2017-01-19 | 2017-01-12 | View |
Page 668 of 17672, showing 5 records out of 88360 total, starting on record 3336, ending on 3340