NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
80906 | CVE-2002-1955 | Iomega NAS A300U uses cleartext LANMAN authentication when mounting CIFS/SMB drives, which allows remote attackers to perform a man-in-the-middle attack. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
54538 | CVE-2007-2371 | admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification before login, which allows remote attackers to cause a denial of service (loss of configuration data), and possibly perform direct static code injection, via a saveGlobalconfig action. | 2 | 10 | High | 2017-01-07 | 2008-09-05 | View | |
57354 | CVE-2007-5278 | Zomplog 3.8.1 and earlier stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers to download files that were uploaded by users, as demonstrated by obtaining a directory listing via a direct request to /upload and then retrieving individual files. NOTE: in a non-default configuration, the directory listing is denied, but filenames may be predicable. | 2 | 4.3 | Medium | 2017-01-07 | 2008-09-05 | View | |
60938 | CVE-2006-2235 | CodeMunkyX (aka free-php.net) Simple Poll 1.0, when authentication is not required for the admin directory, allows remote attackers to gain administrative privileges by appending /admin/ to the top-level URI of the application. | 2 | 7.6 | High | 2016-12-20 | 2008-09-05 | View | |
61450 | CVE-2006-2765 | Cross-site scripting (XSS) vulnerability in news_information.php in Interlink Advantage allows remote attackers to inject arbitrary web script or HTML via the flag parameter. | 2 | 2.6 | Low | 2016-12-20 | 2008-09-05 | View |
Page 94 of 17672, showing 5 records out of 88360 total, starting on record 466, ending on 470