|
313681
|
- |
|
cutephp
|
cutenews
|
Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a temp…
|
CWE-94
Code Injection
|
CVE-2005-1876
|
2024-02-14 01:19 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313682
|
- |
|
flatnuke
|
flatnuke
|
Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be…
|
CWE-94
Code Injection
|
CVE-2005-1894
|
2024-02-14 01:19 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313683
|
7.5 |
HIGH
Network
|
symfony
|
twig
|
The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication inform…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2001-1537
|
2024-02-14 01:19 |
2001-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313684
|
7.5 |
HIGH
Network
|
dlink
|
dsl-504t_firmware
|
D-Link DSL-504T stores usernames and passwords in cleartext in the router configuration file, which allows remote attackers to obtain sensitive information.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2005-1828
|
2024-02-14 01:17 |
2005-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313685
|
7.5 |
HIGH
Network
|
broadcom
|
bluecoat_security_gateway
|
The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which all…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2004-2397
|
2024-02-14 01:17 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313686
|
- |
|
myupb
|
ultimate_php_board
|
Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing the code in the User-Agent header, which is execute…
|
CWE-94
Code Injection
|
CVE-2003-0395
|
2024-02-14 01:14 |
2003-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313687
|
5.5 |
MEDIUM
Local
|
capturix
|
scanshare
|
Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext in capturixss_cfg.ini, which is readable by local users.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2005-2209
|
2024-02-14 01:09 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313688
|
- |
|
-
|
-
|
Rejected reason: **REJECT** Not a valid vulnerability.
|
-
|
CVE-2024-0707
|
2024-02-13 23:15 |
2024-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313689
|
- |
|
-
|
-
|
Rejected reason: **REJECT** This is a duplicate of CVE-2024-1049. Please use CVE-2024-1049 instead.
|
-
|
CVE-2024-1420
|
2024-02-13 00:15 |
2024-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313690
|
7.5 |
HIGH
Network
|
phprank
|
phprank
|
phpRank 1.8 stores the administrative password in plaintext on the server and in the "ap" cookie, which allows remote attackers to retrieve the administrative password.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2002-1800
|
2024-02-10 12:06 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|