Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.0 CVE-2009-1495 Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a d… Web File Explorer No fix yet Fix from $1,6002009-05-01 MEDIUM 5.0 CVE-2008-6770EPSS 6% YourPlace 1.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to a data… Yourplace after 1.0.2 Fix from $1,6002009-04-29 MEDIUM 5.0 CVE-2008-6771EPSS 6% YourPlace 1.0.2 and earlier allows remote attackers to obtain sensitive system information via a direct request via a direct request to user/uploads/… Yourplace after 1.0.2 Fix from $1,6002009-04-29 MEDIUM 5.0 CVE-2008-6774 internettoolbar/edit.php in YourPlace 1.0.2 and earlier does not end execution when an invalid username is detected, which allows remote attackers to… Yourplace after 1.0.2 Fix from $1,6002009-04-29 HIGH 7.2 CVE-2009-1462 The Security Manager in razorCMS before 0.4 does not verify the permissions of every file owned by the apache user account, which is inconsistent wit… Razorcms after 0.3 Fix from $1,9502009-04-28 MEDIUM 5.0 CVE-2008-6755 ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier… Zoneminder Patch available Fix from $1,6002009-04-27 MEDIUM 6.8 CVE-2008-6747 dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges. NOTE: some of t… Dotproject after 2.1.1 Fix from $1,6002009-04-23 MEDIUM 6.4 CVE-2008-6736 Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attackers to (1) add new events via calAdd.php, … Flat Calendar No fix yet Fix from $1,6002009-04-21 MEDIUM 5.0 CVE-2009-1322 ASP Product Catalog 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a… Asp Product Catalog No fix yet Fix from $1,6002009-04-17 HIGH 7.5 CVE-2008-6701 NetScout (formerly Network General) Visualizer V2100 and InfiniStream i1730 do not restrict access to ResourceManager/en_US/domains/add_domain.jsp, w… Ngenius Infinistream Mitigation only Fix from $1,9502009-04-10 HIGH 7.5 CVE-2008-6673 asp/bs_login.asp in QuickerSite 1.8.5 does not properly restrict access to administrative functionality, which allows remote attackers to (1) change … Quickersite No fix yet Fix from $1,9502009-04-08 MEDIUM 5.0 CVE-2008-6674 mailPage.asp in QuickerSite 1.8.5 allows remote attackers to flood e-mail accounts with messages via a large number of requests with a modified sEmai… Quickersite No fix yet Fix from $1,6002009-04-08 MEDIUM 5.0 CVE-2008-6643 LokiCMS 0.3.4 and possibly earlier versions does not properly restrict access to administrative functions, which allows remote attackers to bypass in… Lokicms No fix yet Fix from $1,6002009-04-07 MEDIUM 5.0 CVE-2008-6650 del.php in miniBloggie 1.0 allows remote attackers to delete arbitrary posts via a direct request with a modified post_id parameter, a different vuln… Minibloggie No fix yet Fix from $1,6002009-04-07 MEDIUM 6.8 CVE-2008-6617 Unrestricted file upload vulnerability in adm/visual/upload.php in SiteXS CMS 0.1.1 allows remote attackers to execute arbitrary code by uploading a … Sitexs Cms No fix yet Fix from $1,6002009-04-06 MEDIUM 6.8 CVE-2008-6619 Unrestricted file upload vulnerability in class/ApplyDB.php in ClassSystem 2.3 allows remote attackers to execute arbitrary code by uploading a file … Classsystem No fix yet Fix from $1,6002009-04-06 HIGH 7.5 CVE-2008-6613 uploader.php in minimal-ablog 0.4 does not properly restrict access, which allows remote attackers to gain administrative privileges via a direct req… Minimal Ablog No fix yet Fix from $1,9502009-04-06 MEDIUM 5.0 CVE-2008-6599 cookiecheck.php in CookieCheck 1.0 stores tmp/cc_sessions under the web root with insufficient access control, which allows remote attackers to obtai… Cookiecheck Patch available Fix from $1,6002009-04-03 MEDIUM 6.8 CVE-2008-6603 MoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_hierarchic is set to True, which might allow remote attackers to bypass intended… Moinmoin No fix yet Fix from $1,6002009-04-03 HIGH 7.2 CVE-2009-1235 XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, w… Mac Os X after 10.5.6 Fix from $1,9502009-04-02 MEDIUM 5.0 CVE-2003-1571 Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the… Web Wiz Guestbook No fix yet Fix from $1,6002009-04-02 MEDIUM 5.0 CVE-2008-6580 The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access control, which allows remote atta… Red Reservations No fix yet Fix from $1,6002009-04-02 MEDIUM 5.0 CVE-2009-1223 aspWebCalendar Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to downlo… Aspwebcalendar Mitigation only Fix from $1,6002009-04-02 HIGH 7.5 CVE-2009-1226 core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attacke… Podcast Generator after 1.1 Fix from $1,9502009-04-02 MEDIUM 5.0 CVE-2005-4880 Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain … Jax Guestbook No fix yet Fix from $1,6002009-03-31 MEDIUM 5.1 CVE-2008-6540 DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey val… Dotnetnuke after 4.8.1 Fix from $1,6002009-03-30 HIGH 7.1 CVE-2009-0637 The SCP server in Cisco IOS 12.2 through 12.4, when Role-Based CLI Access is enabled, does not enforce the CLI view configuration for file transfers,… iOS Mitigation only Fix from $1,9502009-03-27 HIGH 7.5 CVE-2008-6535EPSS 6% admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the administrative password via a dire… Paypal Estores No fix yet Fix from $1,9502009-03-26 MEDIUM 5.0 CVE-2009-1085 Piwik 0.2.32 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain th… Matomo after 0.2.32 Fix from $1,6002009-03-25 MEDIUM 6.5 CVE-2009-1077 The Change My Password implementation in the admin interface in Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the RequiresC… Java System Identity Manager Patch available Fix from $1,6002009-03-25