Total
5279 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-6493 | 1 Easy-news | 1 Easy Content Management Publishing | 2017-09-28 | 5.0 MEDIUM | N/A |
Easy Content Management Publishing stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for Database/News.mdb. | |||||
CVE-2008-6388 | 1 4u2ges | 1 Rapid Classified | 2017-09-28 | 5.0 MEDIUM | N/A |
Rapid Classified 3.1 and 3.15 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to cldb.mdb. | |||||
CVE-2008-6382 | 1 Aspportal | 1 Aspportal | 2017-09-28 | 5.0 MEDIUM | N/A |
ASP Portal 3.2.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to ASPPortal.mdb. | |||||
CVE-2008-6374 | 1 Codefixer | 1 Mailinglistpro | 2017-09-28 | 5.0 MEDIUM | N/A |
CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to db/MailingList.mdb. | |||||
CVE-2008-6357 | 1 Donnafontenot | 1 Mycal Personal Events Calendar | 2017-09-28 | 5.0 MEDIUM | N/A |
MyCal Personal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to mycal.mdb. | |||||
CVE-2008-6356 | 1 Donnafontenot | 1 Evcal Events Calendar | 2017-09-28 | 5.0 MEDIUM | N/A |
evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to (1) evcal.mdb and (2) evcal97.mdb. | |||||
CVE-2008-6355 | 1 Thenetguys | 1 Aspired2protect | 2017-09-28 | 5.0 MEDIUM | N/A |
The Net Guys ASPired2Protect stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to ASPired2Protect.mdb. | |||||
CVE-2008-6354 | 1 Thenetguys | 1 Aspired2poll | 2017-09-28 | 5.0 MEDIUM | N/A |
The Net Guys ASPired2poll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to ASPired2poll.mdb. | |||||
CVE-2008-6321 | 1 Cfshopkart | 1 Cf Shopkart | 2017-09-28 | 5.0 MEDIUM | N/A |
CF Shopkart 5.2.2 stores cfshopkart52.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive information, such as usernames and passwords, via a direct request. | |||||
CVE-2008-6302 | 1 Turnkeyforms | 1 Local Classifieds | 2017-09-28 | 7.5 HIGH | N/A |
TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a direct request to Site_Admin/admin.php. | |||||
CVE-2008-6296 | 1 Maran | 1 Php Shop | 2017-09-28 | 7.5 HIGH | N/A |
admin.php in Maran PHP Shop allows remote attackers to bypass authentication and gain administrative access by setting the user cookie to "demo." | |||||
CVE-2008-6294 | 1 Accscripts | 1 Acc Statistics | 2017-09-28 | 7.5 HIGH | N/A |
admin/Index.php in Acc Statistics 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie cookie to "admin." | |||||
CVE-2008-6293 | 1 Accscripts | 1 Acc Real Estate | 2017-09-28 | 7.5 HIGH | N/A |
admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie to "admin." | |||||
CVE-2008-6292 | 1 Accscripts | 1 Acc Autos | 2017-09-28 | 7.5 HIGH | N/A |
Acc Autos 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) username_cookie to "admin," (2) right_cookie to "1," and (3) id_cookie to "1." | |||||
CVE-2008-6291 | 1 Accscripts | 1 Acc Php Email | 2017-09-28 | 7.5 HIGH | N/A |
Acc PHP eMail 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the NEWSLETTERLOGIN cookie to "admin". | |||||
CVE-2008-6199 | 1 2532gigs | 1 2532gigs | 2017-09-28 | 4.0 MEDIUM | N/A |
2532designs 2532|Gigs 1.2.2 and earlier allows remote attackers to trigger a backup and obtain sensitive information via a direct request to backup.php, which creates backup.sql under the web root with insufficient access control. | |||||
CVE-2009-0641 | 1 Freebsd | 1 Freebsd | 2017-09-28 | 9.3 HIGH | N/A |
sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a crafted environment variable from a telnet client, as demonstrated by an LD_PRELOAD value that references a malicious library. | |||||
CVE-2009-0578 | 1 Ubuntu | 1 Ubuntu Linux | 2017-09-28 | 6.2 MEDIUM | N/A |
GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to change or remove the network connections of arbitrary users via unspecified vectors related to org.freedesktop.NetworkManagerUserSettings and at_console. | |||||
CVE-2009-0571 | 1 Ninjadesigns | 1 Mailist | 2017-09-28 | 5.0 MEDIUM | N/A |
admin.php in Ninja Designs Mailist 3.0 stores backup copies of maillist.php under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to the backup directory. | |||||
CVE-2009-0536 | 1 Ibm | 1 Aix | 2017-09-28 | 4.9 MEDIUM | N/A |
at in bos.rte.cron on IBM AIX 5.2.0, 5.3.0 through 5.3.9, and 6.1.0 through 6.1.2 allows local users to read arbitrary files via unspecified vectors, related to failure to drop root privileges. |