Total
5210 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-6356 | 1 Donnafontenot | 1 Evcal Events Calendar | 2017-09-29 | 5.0 MEDIUM | N/A |
evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to (1) evcal.mdb and (2) evcal97.mdb. | |||||
CVE-2008-6871 | 1 Merlix | 1 Educate Server | 2017-09-29 | 5.0 MEDIUM | N/A |
Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers to obtain unspecified sensitive information via a direct request. | |||||
CVE-2008-6494 | 1 Robs-projects | 1 Asp User Engine.net | 2017-09-29 | 5.0 MEDIUM | N/A |
ASP User Engine.NET stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for users.mdb. | |||||
CVE-2008-6869 | 1 Oramon | 1 Oramon | 2017-09-29 | 5.0 MEDIUM | N/A |
Oramon Oracle Database Monitoring Tool 2.0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for config/oramon.ini. | |||||
CVE-2008-6870 | 1 Merlix | 1 Educate Server | 2017-09-29 | 5.0 MEDIUM | N/A |
Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information via a direct request to (1) config.asp and (2) users.asp. | |||||
CVE-2008-6493 | 1 Easy-news | 1 Easy Content Management Publishing | 2017-09-29 | 5.0 MEDIUM | N/A |
Easy Content Management Publishing stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for Database/News.mdb. | |||||
CVE-2008-6580 | 1 Funscripts | 1 Red Reservations | 2017-09-29 | 5.0 MEDIUM | N/A |
The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database via a direct request to (1) makered.mdb and (2) makered97.mdb. | |||||
CVE-2008-6914 | 1 Zeeways | 1 Zeeproperty | 2017-09-29 | 6.5 MEDIUM | N/A |
Unrestricted file upload vulnerability in viewprofile.php in Zeeways ZEEPROPERTY 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a photo in a profile modification, then accessing a related file via a direct request to the file in companylogo/. | |||||
CVE-2008-6921 | 1 W2b | 1 Phpadboard | 2017-09-29 | 7.5 HIGH | N/A |
Unrestricted file upload vulnerability in index.php in phpAdBoard 1.8 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in photoes/. | |||||
CVE-2009-0399 | 1 Chipmunk Scripts | 1 Chipmunk Blogger | 2017-09-29 | 7.5 HIGH | N/A |
Chipmunk Blogger Script allows remote attackers to gain administrator privileges via a direct request to admin/reguser.php. NOTE: this is only a vulnerability when the administrator does not properly follow installation directions. | |||||
CVE-2008-6957 | 1 Discuz | 1 Discuz\! | 2017-09-29 | 7.5 HIGH | N/A |
member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasswd actions, possibly involving predictable generation of the id parameter. | |||||
CVE-2008-6931 | 1 Phpstore | 1 Phpcareers | 2017-09-29 | 6.5 MEDIUM | N/A |
Unrestricted file upload vulnerability in PHPStore Job Search (aka PHPCareers) allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a resume photo, then accessing it via a direct request to the file in jobseekers/jobseeker_profile_images. | |||||
CVE-2008-6199 | 1 2532gigs | 1 2532gigs | 2017-09-29 | 4.0 MEDIUM | N/A |
2532designs 2532|Gigs 1.2.2 and earlier allows remote attackers to trigger a backup and obtain sensitive information via a direct request to backup.php, which creates backup.sql under the web root with insufficient access control. | |||||
CVE-2008-7118 | 1 Webidsupport | 1 Webid | 2017-09-29 | 5.0 MEDIUM | N/A |
WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain SQL query logs via a direct request for logs/cron.log. | |||||
CVE-2008-6920 | 1 W2b | 1 Phpemployment | 2017-09-29 | 7.5 HIGH | N/A |
Unrestricted file upload vulnerability in auth.php in phpEmployment 1.8 allows remote attackers to execute arbitrary code by uploading a file with an executable extension during a regnew action, then accessing it via a direct request to the file in photoes/. | |||||
CVE-2008-7188 | 1 Clip-share | 1 Clipshare | 2017-09-29 | 7.5 HIGH | N/A |
ClipShare 2.6 does not properly restrict access to certain functionality, which allows remote attackers to change the profile of arbitrary users via a modified uid variable to siteadmin/useredit.php. NOTE: this can be used to recover the password of the user by using the modified e-mail address in the email parameter to recoverpass.php. | |||||
CVE-2008-6932 | 1 Alstrasoft | 1 Sendit | 2017-09-29 | 7.5 HIGH | N/A |
Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in send/files/. | |||||
CVE-2008-7076 | 1 Kalptaru Infotech | 1 Stararticles | 2017-09-29 | 6.5 MEDIUM | N/A |
Unrestricted file upload vulnerability in user.modify.profile.php in Kalptaru Infotech Ltd. Star Articles 6.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile photo, then accessing it via a direct request to the file in authorphoto/. | |||||
CVE-2008-7157 | 1 Ekinboard | 1 Ekinboard | 2017-09-29 | 6.8 MEDIUM | N/A |
Unrestricted file upload vulnerability in EkinBoard 1.1.0 and earlier allows remote attackers to execute arbitrary code by uploading an avatar file with an executable extension followed by a safe extension, then accessing it via a direct request to the file in uploaded/avatars/. | |||||
CVE-2009-0249 | 1 Katywhitton | 1 Rankem | 2017-09-29 | 5.0 MEDIUM | N/A |
Katy Whitton RankEm stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for database/topsites.mdb. |