NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
37024  CVE-2013-0731  ajax.functions.php in the MailUp plugin before 1.3.3 for WordPress does not properly restrict access to unspecified Ajax functions, which allows remote attackers to modify plugin settings and conduct cross-site scripting (XSS) attacks by setting the wordpress_logged_in cookie. NOTE: this is due to an incomplete fix for a similar issue that was fixed in 1.3.2.    Medium  2017-01-18  2013-04-05  View
43707  CVE-2012-1840  AjaXplorer 3.2.x before 3.2.5 and 4.0.x before 4.0.4 does not properly perform cookie authentication, which allows remote attackers to obtain login access by leveraging knowledge of a password hash.    7.5  High  2017-01-19  2012-04-12  View
48898  CVE-2009-1629  ajaxterm.js in AjaxTerm 0.10 and earlier generates session IDs with predictable random numbers based on certain JavaScript functions, which makes it easier for remote attackers to (1) hijack a session or (2) cause a denial of service (session ID exhaustion) via a brute-force attack.    6.8  Medium  2017-01-07  2011-01-19  View
52385  CVE-2007-0153  AJLogin 3.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for ajlogin.mdb.    7.5  High  2017-01-07  2008-11-15  View
20384  CVE-2016-4853  AKABEi SOFT2 games allow remote attackers to execute arbitrary OS commands via crafted saved data, as demonstrated by Happy Wardrobe.    6.8  Medium  2017-01-19  2016-11-28  View

Page 902 of 17672, showing 5 records out of 88360 total, starting on record 4506, ending on 4510

Actions