NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
71950  CVE-2004-1571  AJ-Fork 167 allows remote attackers to gain sensitive information via a direct request to (1) auto-acronyms.php, (2) auto-archive.php, (3) ount-article-views.php, (4) kses.php, (5) custom-quick-tags.php, (6) disable-all-comments.php, (7) easy-date-format.php, (8) enable-disable-comments.php, (9) filter-by-author.php, (10) format-switcher.php, (11) long-to-short.php, (12) prospective-posting.php, or (13) sort-by-xfield.php, which displays the full path in an error message.    Medium  2017-07-18  2017-07-10  View
71951  CVE-2004-1572  AJ-Fork 167 does not restrict access to directories such as (1) data, (2) inc, (3) plugins, (4) skins, or (5) tools, which allows remote attackers to list files in those directories via a direct HTTP request.    Medium  2017-07-18  2017-07-10  View
40277  CVE-2013-4731  ajax.cgi in the web interface on the Choice Wireless Green Packet WIXFMR-111 4G WiMax modem allows remote attackers to execute arbitrary commands via shell metacharacters in the pip parameter in an Ajax tag_ipPing request, a different vulnerability than CVE-2013-3581.    9.3  High  2017-01-18  2013-07-17  View
39351  CVE-2013-3581  ajax.cgi in the web interface on the Choice Wireless Green Packet WIXFMR-111 4G WiMax modem allows remote attackers to obtain sensitive information via an Ajax (1) wmxState or (2) netState request.    7.1  High  2017-01-18  2013-10-11  View
38617  CVE-2013-2640  ajax.functions.php in the MailUp plugin before 1.3.2 for WordPress does not properly restrict access to unspecified Ajax functions, which allows remote attackers to modify plugin settings and conduct cross-site scripting (XSS) attacks via unspecified vectors related to "formData=save" requests, a different version than CVE-2013-0731.    Medium  2017-01-18  2013-04-05  View

Page 901 of 17672, showing 5 records out of 88360 total, starting on record 4501, ending on 4505

Actions