NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
37024 | CVE-2013-0731 | ajax.functions.php in the MailUp plugin before 1.3.3 for WordPress does not properly restrict access to unspecified Ajax functions, which allows remote attackers to modify plugin settings and conduct cross-site scripting (XSS) attacks by setting the wordpress_logged_in cookie. NOTE: this is due to an incomplete fix for a similar issue that was fixed in 1.3.2. | 2 | 5 | Medium | 2017-01-18 | 2013-04-05 | View | |
43707 | CVE-2012-1840 | AjaXplorer 3.2.x before 3.2.5 and 4.0.x before 4.0.4 does not properly perform cookie authentication, which allows remote attackers to obtain login access by leveraging knowledge of a password hash. | 2 | 7.5 | High | 2017-01-19 | 2012-04-12 | View | |
48898 | CVE-2009-1629 | ajaxterm.js in AjaxTerm 0.10 and earlier generates session IDs with predictable random numbers based on certain JavaScript functions, which makes it easier for remote attackers to (1) hijack a session or (2) cause a denial of service (session ID exhaustion) via a brute-force attack. | 2 | 6.8 | Medium | 2017-01-07 | 2011-01-19 | View | |
52385 | CVE-2007-0153 | AJLogin 3.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for ajlogin.mdb. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
20384 | CVE-2016-4853 | AKABEi SOFT2 games allow remote attackers to execute arbitrary OS commands via crafted saved data, as demonstrated by Happy Wardrobe. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 902 of 17672, showing 5 records out of 88360 total, starting on record 4506, ending on 4510