Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Web File Explorer MEDIUM 5.0
CVE-2009-1495

Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a d…

No fix yet
Fix from $1,600 2009-05-01
Yourplace MEDIUM 5.0
CVE-2008-6770EPSS 6%

YourPlace 1.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to a data…

Fix: after 1.0.2
Fix from $1,600 2009-04-29
Yourplace MEDIUM 5.0
CVE-2008-6771EPSS 6%

YourPlace 1.0.2 and earlier allows remote attackers to obtain sensitive system information via a direct request via a direct request to user/uploads/…

Fix: after 1.0.2
Fix from $1,600 2009-04-29
Yourplace MEDIUM 5.0
CVE-2008-6774

internettoolbar/edit.php in YourPlace 1.0.2 and earlier does not end execution when an invalid username is detected, which allows remote attackers to…

Fix: after 1.0.2
Fix from $1,600 2009-04-29
Razorcms HIGH 7.2
CVE-2009-1462

The Security Manager in razorCMS before 0.4 does not verify the permissions of every file owned by the apache user account, which is inconsistent wit…

Fix: after 0.3
Fix from $1,950 2009-04-28
Zoneminder MEDIUM 5.0
CVE-2008-6755

ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier…

Patch available
Fix from $1,600 2009-04-27
Dotproject MEDIUM 6.8
CVE-2008-6747

dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges. NOTE: some of t…

Fix: after 2.1.1
Fix from $1,600 2009-04-23
Flat Calendar MEDIUM 6.4
CVE-2008-6736

Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attackers to (1) add new events via calAdd.php, …

No fix yet
Fix from $1,600 2009-04-21
Asp Product Catalog MEDIUM 5.0
CVE-2009-1322

ASP Product Catalog 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a…

No fix yet
Fix from $1,600 2009-04-17
Ngenius Infinistream HIGH 7.5
CVE-2008-6701

NetScout (formerly Network General) Visualizer V2100 and InfiniStream i1730 do not restrict access to ResourceManager/en_US/domains/add_domain.jsp, w…

Mitigation only
Fix from $1,950 2009-04-10
Quickersite HIGH 7.5
CVE-2008-6673

asp/bs_login.asp in QuickerSite 1.8.5 does not properly restrict access to administrative functionality, which allows remote attackers to (1) change …

No fix yet
Fix from $1,950 2009-04-08
Quickersite MEDIUM 5.0
CVE-2008-6674

mailPage.asp in QuickerSite 1.8.5 allows remote attackers to flood e-mail accounts with messages via a large number of requests with a modified sEmai…

No fix yet
Fix from $1,600 2009-04-08
Lokicms MEDIUM 5.0
CVE-2008-6643

LokiCMS 0.3.4 and possibly earlier versions does not properly restrict access to administrative functions, which allows remote attackers to bypass in…

No fix yet
Fix from $1,600 2009-04-07
Minibloggie MEDIUM 5.0
CVE-2008-6650

del.php in miniBloggie 1.0 allows remote attackers to delete arbitrary posts via a direct request with a modified post_id parameter, a different vuln…

No fix yet
Fix from $1,600 2009-04-07
Sitexs Cms MEDIUM 6.8
CVE-2008-6617

Unrestricted file upload vulnerability in adm/visual/upload.php in SiteXS CMS 0.1.1 allows remote attackers to execute arbitrary code by uploading a …

No fix yet
Fix from $1,600 2009-04-06
Classsystem MEDIUM 6.8
CVE-2008-6619

Unrestricted file upload vulnerability in class/ApplyDB.php in ClassSystem 2.3 allows remote attackers to execute arbitrary code by uploading a file …

No fix yet
Fix from $1,600 2009-04-06
Minimal Ablog HIGH 7.5
CVE-2008-6613

uploader.php in minimal-ablog 0.4 does not properly restrict access, which allows remote attackers to gain administrative privileges via a direct req…

No fix yet
Fix from $1,950 2009-04-06
Cookiecheck MEDIUM 5.0
CVE-2008-6599

cookiecheck.php in CookieCheck 1.0 stores tmp/cc_sessions under the web root with insufficient access control, which allows remote attackers to obtai…

Patch available
Fix from $1,600 2009-04-03
Moinmoin MEDIUM 6.8
CVE-2008-6603

MoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_hierarchic is set to True, which might allow remote attackers to bypass intended…

No fix yet
Fix from $1,600 2009-04-03
Mac Os X HIGH 7.2
CVE-2009-1235

XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, w…

Fix: after 10.5.6
Fix from $1,950 2009-04-02
Web Wiz Guestbook MEDIUM 5.0
CVE-2003-1571

Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the…

No fix yet
Fix from $1,600 2009-04-02
Red Reservations MEDIUM 5.0
CVE-2008-6580

The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access control, which allows remote atta…

No fix yet
Fix from $1,600 2009-04-02
Aspwebcalendar MEDIUM 5.0
CVE-2009-1223

aspWebCalendar Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to downlo…

Mitigation only
Fix from $1,600 2009-04-02
Podcast Generator HIGH 7.5
CVE-2009-1226

core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attacke…

Fix: after 1.1
Fix from $1,950 2009-04-02
Jax Guestbook MEDIUM 5.0
CVE-2005-4880

Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain …

No fix yet
Fix from $1,600 2009-03-31
Dotnetnuke MEDIUM 5.1
CVE-2008-6540

DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey val…

Fix: after 4.8.1
Fix from $1,600 2009-03-30
iOS HIGH 7.1
CVE-2009-0637

The SCP server in Cisco IOS 12.2 through 12.4, when Role-Based CLI Access is enabled, does not enforce the CLI view configuration for file transfers,…

Mitigation only
Fix from $1,950 2009-03-27
Paypal Estores HIGH 7.5
CVE-2008-6535EPSS 6%

admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the administrative password via a dire…

No fix yet
Fix from $1,950 2009-03-26
Matomo MEDIUM 5.0
CVE-2009-1085

Piwik 0.2.32 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain th…

Fix: after 0.2.32
Fix from $1,600 2009-03-25
Java System Identity Manager MEDIUM 6.5
CVE-2009-1077

The Change My Password implementation in the admin interface in Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the RequiresC…

Patch available
Fix from $1,600 2009-03-25