|
313341
|
7.5 |
HIGH
Network
|
kde debian
|
kde debian_linux
|
The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and…
|
CWE-281
Improper Preservation of Permissions
|
CVE-2005-1920
|
2024-01-26 06:11 |
2005-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313342
|
- |
|
baalsystems
|
baal_smart_forms
|
Baal Smart Forms before 3.2 allows remote attackers to bypass authentication and obtain system access via a direct request to regadmin.php.
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2004-2144
|
2024-01-26 06:11 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313343
|
- |
|
phpmyfaq
|
phpmyfaq
|
phpMyFAQ 1.4.0 allows remote attackers to access the Image Manager to upload or delete images without authorization via a direct request.
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2004-2257
|
2024-01-26 06:11 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313344
|
7.5 |
HIGH
Network
|
sun
|
solaris_pc_netlink
|
Sun PC NetLink 1.0 through 1.2 does not properly set the access control list (ACL) for files and directories that use symbolic links and have been restored from backup, which could allow local or rem…
|
CWE-59 CWE-281
Link Following Improper Preservation of Permissions
|
CVE-2002-2323
|
2024-01-26 06:11 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313345
|
7.5 |
HIGH
Network
|
microsoft
|
windows_2000
|
Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories and automatically modify the inherited NTFS permissions, which may cause the directories to have less r…
|
CWE-281
Improper Preservation of Permissions
|
CVE-2001-1515
|
2024-01-26 06:11 |
2001-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313346
|
7.8 |
HIGH
Local
|
debian
|
debian_linux
|
sash before 3.4-4 in Debian GNU/Linux does not properly clone /etc/shadow, which makes it world-readable and could allow local users to gain privileges via password cracking.
|
CWE-281
Improper Preservation of Permissions
|
CVE-2001-0195
|
2024-01-26 06:11 |
2001-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313347
|
- |
|
flatnuke
|
flatnuke
|
FlatNuke 2.5.3 allows remote attackers to cause a denial of service or obtain sensitive information via (1) a direct request to foot_news.php, which triggers an infinite loop, or (2) direct requests …
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2005-1892
|
2024-01-26 06:10 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313348
|
7.8 |
HIGH
Local
|
silvercity_project
|
silvercity
|
SilverCity before 0.9.5-r1 installs (1) cgi-styler-form.py, (2) cgi-styler.py, and (3) source2html.py with read and write world permissions, which allows local users to execute arbitrary code.
|
CWE-276
Incorrect Default Permissions
|
CVE-2005-1941
|
2024-01-26 06:09 |
2005-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313349
|
- |
|
dlink
|
dsl-504t_firmware
|
D-Link DSL-504T allows remote attackers to bypass authentication and gain privileges, such as upgrade firmware, restart the router or restore a saved configuration, via a direct request to firmwarecf…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2005-1827
|
2024-01-26 06:08 |
2005-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313350
|
- |
|
postnuke
|
postnuke
|
PostNuke 0.750 and 0.760RC3 allows remote attackers to obtain sensitive information via a direct request to (1) theme.php or (2) Xanthia.php in the Xanthia module, (3) user.php, (4) thelang.php, (5) …
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2005-1698
|
2024-01-26 06:08 |
2005-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|