Total
5210 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2009-2024 | 1 Vt.rovno | 1 Asp Vt Auth | 2017-09-29 | 5.0 MEDIUM | N/A |
Vlad Titarenko ASP VT Auth 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file and obtain usernames and passwords via a direct request for zHk8dEes3.txt. | |||||
CVE-2009-1821 | 1 Dmxready | 1 Registration Manager | 2017-09-29 | 5.0 MEDIUM | N/A |
DMXReady Registration Manager 1.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for databases/webblogmanager.mdb. | |||||
CVE-2009-1322 | 1 Humayun Shabbir Bhutta | 1 Asp Product Catalog | 2017-09-29 | 5.0 MEDIUM | N/A |
ASP Product Catalog 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for database/aspProductCatalog.mdb. | |||||
CVE-2009-1771 | 1 Flyspeck | 1 Flyspeck Cms | 2017-09-29 | 7.5 HIGH | N/A |
index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which allows remote attackers to create or modify admin accounts via the (1) users[fullname], (2) users[email], (3) users[role_id], (4) users[username], and (5) users[password] parameters. | |||||
CVE-2009-1767 | 1 2daybiz | 1 Template Monster Clone | 2017-09-29 | 5.0 MEDIUM | N/A |
admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter. | |||||
CVE-2009-2025 | 1 Dutchmonkey | 1 Dm Filemanager | 2017-09-29 | 7.5 HIGH | N/A |
admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access by setting the (1) USER, (2) GROUPID, (3) GROUP, and (4) USERID cookies to certain values. | |||||
CVE-2009-1226 | 1 Podcast Generator | 1 Podcast Generator | 2017-09-29 | 7.5 HIGH | N/A |
core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attackers to delete arbitrary files via the file parameter. | |||||
CVE-2009-0767 | 1 Bookelves | 1 Kipper | 2017-09-29 | 5.0 MEDIUM | N/A |
Kipper 2.01 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing credentials via a direct request for job/config.data. | |||||
CVE-2016-5853 | 1 Google | 1 Android | 2017-09-29 | 7.6 HIGH | 7.0 HIGH |
In an audio driver in all Qualcomm products with Android releases from CAF using the Linux kernel, when a sanity check encounters a length value not in the correct range, an error message is printed, but code execution continues in the same way as for a correct length value. | |||||
CVE-2009-1550 | 1 Zakkis | 1 Abc Advertise | 2017-09-29 | 5.0 MEDIUM | N/A |
Zakkis Technology ABC Advertise 1.0 does not properly restrict access to admin.inc.php, which allows remote attackers to obtain the administrator login name and password via a direct request. | |||||
CVE-2009-1582 | 1 Kalptarudemos | 1 Million Dollar Text Links | 2017-09-29 | 7.5 HIGH | N/A |
Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote attackers to bypass intended restrictions and gain privileges via a direct request to admin.home.php after visiting admin.php. | |||||
CVE-2009-1840 | 1 Mozilla | 3 Firefox, Seamonkey, Thunderbird | 2017-09-29 | 9.3 HIGH | N/A |
Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated by a "web bug" in an e-mail message, or web script or an advertisement in a web page. | |||||
CVE-2015-7875 | 1 Chaos Tool Suite Project | 1 Ctools | 2017-09-29 | 5.0 MEDIUM | 7.5 HIGH |
ctools 6.x-1.x before 6.x-1.14 and 7.x-1.x before 7.x-1.8 in Drupal does not verify the "edit" permission for the "content type" plugins that are used on Panels and similar systems to place content and functionality on a page. | |||||
CVE-2009-2080 | 1 Mrcgiguy | 1 The Ticket System | 2017-09-29 | 7.5 HIGH | N/A |
admin.php in MRCGIGUY The Ticket System 2.0 does not properly restrict access, which allows remote attackers to (1) obtain sensitive configuration information via the editconfig action or (2) change the administrator's password via the id parameter in an editop action. | |||||
CVE-2009-2022 | 1 Fipsasp | 1 Fipscms Light | 2017-09-29 | 5.0 MEDIUM | N/A |
fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file and obtain sensitive information via a direct request for _fipsdb/db.mdb. | |||||
CVE-2009-1665 | 1 Easy-scripts | 1 Answer And Question Script | 2017-09-29 | 6.4 MEDIUM | N/A |
myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to remove arbitrary user accounts via a modified userid parameter without specifying any additional fields. | |||||
CVE-2009-0760 | 1 Team5 | 1 Team Board | 2017-09-29 | 5.0 MEDIUM | N/A |
Team Board 1.x and 2.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for data/team.mdb. | |||||
CVE-2009-1652 | 1 2daybiz | 1 Business Community Script | 2017-09-29 | 7.5 HIGH | N/A |
admin/adminaddeditdetails.php in Business Community Script does not properly restrict access, which allows remote attackers to gain privileges and add administrators via a direct request. | |||||
CVE-2009-1235 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2017-09-29 | 7.2 HIGH | N/A |
XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, which allows local users to overwrite kernel memory and gain privileges by attaching an HFS+ disk image and performing certain steps involving HFS_GET_BOOT_INFO fcntl calls. | |||||
CVE-2009-1610 | 1 Jobscript | 1 Job Script Job Board Software | 2017-09-29 | 7.5 HIGH | N/A |
admin/changepassword.php in Job Script Job Board Software 2.0 allows remote attackers to change the administrator password and gain administrator privileges via a direct request. |