|
313351
|
- |
|
episodex
|
episodex_guestbook
|
episodex guestbook allows remote attackers to bypass authentication and edit scripts via a direct request to admin.asp.
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2005-1685
|
2024-01-26 06:07 |
2005-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313352
|
9.1 |
CRITICAL
Network
|
midicart
|
midicart_php midicart_php_plus midicart_php_maxi
|
MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or (2) access sensitive information via a direct request to adm…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2002-1798
|
2024-01-26 06:04 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313353
|
- |
|
hostingcontroller
|
hosting_controller
|
Hosting Controller 6.1 Hotfix 1.9 and earlier allows remote attackers to register arbitrary users via a direct request to addsubsite.asp with the loginname and password parameters set.
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2005-1654
|
2024-01-26 06:03 |
2005-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313354
|
- |
|
yusasp
|
web_asset_manager
|
YusASP Web Asset Manager 1.0 allows remote attackers to gain privileges via a direct request to assetmanager.asp.
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2005-1668
|
2024-01-26 06:03 |
2005-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313355
|
7.5 |
HIGH
Network
|
iomega
|
nas_a300u_firmware
|
The Network Attached Storage (NAS) Administration Web Page for Iomega NAS A300U transmits passwords in cleartext, which allows remote attackers to sniff the administrative password.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2002-1949
|
2024-01-26 06:00 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313356
|
7.5 |
HIGH
Network
|
procom
|
netforce_800_firmware
|
Procom NetFORCE 800 4.02 M10 Build 20 and possibly other versions sends the NIS password map (passwd.nis) as a file attachment in diagnostic e-mail messages, which allows remote attackers to obtain t…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2005-3140
|
2024-01-26 05:58 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313357
|
- |
|
solarwinds
|
dameware_mini_remote_control
|
DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to gain sensitive information.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2004-1852
|
2024-01-26 05:57 |
2004-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313358
|
5.5 |
MEDIUM
Local
|
macromedia
|
coldfusion
|
ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to access trusted Java objects without usin…
|
CWE-470
Unsafe Reflection
|
CVE-2004-2331
|
2024-01-25 11:16 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313359
|
9.8 |
CRITICAL
Network
|
mozilla sco
|
mozilla openserver
|
The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, whic…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2003-0791
|
2024-01-25 11:14 |
2003-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313360
|
- |
|
-
|
-
|
Rejected reason: ** REJECT **
DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-5533. Reason: This record is a reservation duplicate of CVE-2023-5533. Notes: All CVE users should reference CVE-2023-55…
|
-
|
CVE-2023-5656
|
2024-01-24 08:15 |
2023-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|