Total
5210 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-5931 | 1 The Net Guys | 1 Aspired2blog | 2017-09-29 | 5.0 MEDIUM | N/A |
The Net Guys ASPired2Blog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for admin/blog.mdb. NOTE: some of these details are obtained from third party information. | |||||
CVE-2008-5601 | 1 Robs-projects | 1 Asp User Engine | 2017-09-29 | 5.0 MEDIUM | N/A |
User Engine Lite ASP stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for users.mdb. | |||||
CVE-2008-4600 | 1 Steve Dawson | 1 Pokermax Poker League Tournament Script | 2017-09-29 | 7.5 HIGH | N/A |
configure.php in PokerMax Poker League Tournament Script 0.13 allows remote attackers to bypass authentication and gain administrative access by setting the ValidUserAdmin cookie. | |||||
CVE-2008-5951 | 1 Aspapps | 1 Template Creature | 2017-09-29 | 5.0 MEDIUM | N/A |
ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for workDB/templatemonster.mdb. | |||||
CVE-2008-5855 | 1 Myphpscripts | 1 Login Session | 2017-09-29 | 5.0 MEDIUM | N/A |
myPHPscripts Login Session 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover usernames, e-mail addresses, and password hashes via a direct request for users.txt. | |||||
CVE-2008-5603 | 1 Aspapps | 1 Aspticker | 2017-09-29 | 5.0 MEDIUM | N/A |
ASPTicker 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for news.mdb. | |||||
CVE-2008-4921 | 1 Chipmunk Scripts | 1 Chipmunk Cms | 2017-09-29 | 7.5 HIGH | N/A |
board/admin/reguser.php in Chipmunk CMS 1.3 allows remote attackers to bypass authentication and gain administrator privileges via a direct request. NOTE: some of these details are obtained from third party information. | |||||
CVE-2008-4451 | 1 Eset Software | 1 System Analyzer Tool | 2017-09-29 | 7.2 HIGH | N/A |
The SysInspector AntiStealth driver (esiasdrv.sys) 3.0.65535.0 in ESET System Analyzer Tool 1.1.1.0 allows local users to execute arbitrary code via a certain METHOD_NEITHER IOCTL request to \Device\esiasdrv that overwrites a pointer. | |||||
CVE-2008-5600 | 1 Merlix | 1 Teamworx Server | 2017-09-29 | 5.0 MEDIUM | N/A |
Merlix Teamworx Server stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for teamworx.mdb. | |||||
CVE-2008-5765 | 1 2500mhz | 1 Worksimple | 2017-09-29 | 5.0 MEDIUM | N/A |
WorkSimple 1.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for data/usr.txt. | |||||
CVE-2008-5762 | 1 Mariovaldez | 1 Simple Text-file Login Script | 2017-09-29 | 5.0 MEDIUM | N/A |
Simple Text-File Login Script (SiTeFiLo) 1.0.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for slog_users.txt. | |||||
CVE-2008-5780 | 1 Hostforest | 1 Forest Blog | 2017-09-29 | 5.0 MEDIUM | N/A |
Forest Blog 1.3.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing passwords via a direct request for blog.mdb. | |||||
CVE-2008-5897 | 1 Codeavalanche | 1 Freewallpaper | 2017-09-29 | 7.5 HIGH | N/A |
CodeAvalanche FreeWallpaper stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CAFreeWallpaper.mdb. NOTE: some of these details are obtained from third party information. | |||||
CVE-2008-5899 | 1 Codeavalanche | 1 Freeforall | 2017-09-29 | 7.5 HIGH | N/A |
CodeAvalanche FreeForAll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CAFFAPage.mdb. NOTE: some of these details are obtained from third party information. | |||||
CVE-2008-4341 | 1 Myblog | 1 Myblog | 2017-09-29 | 7.5 HIGH | N/A |
add.php in MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication and gain administrative access by setting a cookie with admin=yes and login=admin. | |||||
CVE-2008-5852 | 1 Emefa | 1 Emefa Guestbook | 2017-09-29 | 5.0 MEDIUM | N/A |
Emefa Guestbook 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for guestbook.mdb. | |||||
CVE-2008-5981 | 1 Pacosdrivers | 1 Pacpoll | 2017-09-29 | 5.0 MEDIUM | N/A |
PacPoll 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) poll.mdb or (2) poll97.mdb. | |||||
CVE-2008-5608 | 1 Aspapps | 1 Asp Autodealer | 2017-09-29 | 5.0 MEDIUM | N/A |
ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for auto.mdb. | |||||
CVE-2008-4245 | 1 Rianxosencabos Cms | 1 Rianxosencabos Cms | 2017-09-29 | 6.5 MEDIUM | N/A |
The Admin Control Panel in Rianxosencabos CMS 0.9 does not require administrator privileges, which allows remote authenticated users to (1) change a user's privileges, (2) delete a user account, or perform unspecified other administrative actions via vectors involving an admin lista action to the default URI, possibly related to useradmin.php. | |||||
CVE-2008-5560 | 1 Dazzlindonna | 1 Postecards | 2017-09-29 | 5.0 MEDIUM | N/A |
PostEcards stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for postcards.mdb. |