NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
80249 | CVE-2002-1276 | An incomplete fix for a cross-site scripting (XSS) vulnerability in SquirrelMail 1.2.8 calls the strip_tags function on the PHP_SELF value but does not save the result back to that variable, leaving it open to cross-site scripting attacks. | 2 | 4.3 | Medium | 2017-01-05 | 2008-09-05 | View | |
80761 | CVE-2002-1810 | D-Link DWL-900AP+ Access Point 2.1 and 2.2 allows remote attackers to access the TFTP server without authentication and read the config.img file, which contains sensitive information such as the administrative password, the WEP encryption keys, and network configuration information. | 2 | 7.5 | High | 2017-01-05 | 2008-09-05 | View | |
81017 | CVE-2002-2066 | BestCrypt BCWipe 1.0.7 and 2.0 through 2.35.1 does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
81273 | CVE-2002-2322 | Ultimate PHP Board (UPB) 1.0b stores the users.dat data file under the web root with insufficient access control, which allows remote attackers to obtain usernames and passwords. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
54137 | CVE-2007-1967 | ** DISPUTED ** PHP remote file inclusion vulnerability in index.php in stat12 allows remote attackers to execute arbitrary PHP code via a URL in the langpath parameter. NOTE: this issue was published by an unreliable researcher, and there is little information to determine which product is actually affected. This is probably an invalid report based on analysis by CVE and a third party. | 2 | 6.8 | Medium | 2017-01-07 | 2008-09-05 | View |
Page 806 of 17672, showing 5 records out of 88360 total, starting on record 4026, ending on 4030