Latest CVE Feed
-
4.0
MEDIUMCVE-2008-4581
The Editor in IBM ENOVIA SmarTeam 5 before release 18 SP5, and release 19 before SP01, allows remote authenticated users to bypass intended access restrictions and read Document objects via the Workflow Process (aka Flow Process) view.... Read more
Affected Products : enovia_smarteam- Published: Oct. 15, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2008-5742
Multiple open redirect vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the redirect parameter in a logoff action to modules/auth/index.php or (2) the url ... Read more
Affected Products : netcat- Published: Dec. 26, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-4258
Absolute path traversal vulnerability in the get functionality in Anti-Spam SMTP Proxy (ASSP) allows remote authenticated users to read arbitrary files via (1) C:\ (Windows drive letter), (2) UNC, and possibly other types of paths in the file parameter.... Read more
Affected Products : anti-spam_smtp_proxy_server- Published: Aug. 21, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2020-13308
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. A user without 2 factor authentication enabled could be prohibited from accessing GitLab by being invited into a project that had 2 factor authentication inheritance.... Read more
Affected Products : gitlab- Published: Sep. 15, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2006-3336
TWiki 01-Dec-2000 up to 4.0.3 allows remote attackers to bypass the upload filter and execute arbitrary code via filenames with double extensions such as ".php.en", ".php.1", and other allowed extensions that are not .txt. NOTE: this is only a vulnerabil... Read more
Affected Products : twiki- Published: Jul. 05, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2008-6098
Bugzilla 3.2 before 3.2 RC2, 3.0 before 3.0.6, 2.22 before 2.22.6, 2.20 before 2.20.7, and other versions after 2.17.4 allows remote authenticated users to bypass moderation to approve and disapprove quips via a direct request to quips.cgi with the action... Read more
Affected Products : bugzilla- Published: Feb. 09, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-5119
Multiple cross-site scripting (XSS) vulnerabilities in Zen Cart 1.3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) admin_name or (2) admin_pass parameter in (a) admin/login.php, or the (3) admin_email parameter in (b) admin/pa... Read more
- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-3859
IBM Informix Dynamic Server (IDS) allows remote authenticated users to create and overwrite arbitrary files via the (1) LOTOFILE and (2) trl_tracefile_set functions, and the (3) "SET DEBUG FILE" commands.... Read more
Affected Products : informix_dynamic_database_server- Published: Aug. 17, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-3377
Cross-site scripting (XSS) vulnerability in JMB Software AutoRank PHP 3.02 and earlier, and AutoRank Pro 5.01 and earlier, allows remote attackers to inject arbitrary web script or HTML via the (1) Keyword parameter in search.php and the (2) Username para... Read more
Affected Products : autorank- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2009-2116
Directory traversal vulnerability in admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to list directory contents via a .. (dot dot) in the dir parameter.... Read more
Affected Products : skybluecanvas- Published: Jun. 18, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2008-7011
The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and Shadow Ops, allows remote authenticated users to cause a denial of service (server exit) via multiple file downloads fro... Read more
- Published: Aug. 19, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2009-1805
Unspecified vulnerability in the VMware Descheduled Time Accounting driver in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, VMware Server 1.x before 1.0.9 build 156507 and 2.x before 2.0.1 build 15674... Read more
- Published: Jun. 01, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2009-0700
Plunet BusinessManager 4.1 and earlier allows remote authenticated users to bypass access restrictions and (1) read sensitive Customer or Order data via a modified Pfad parameter to pagesUTF8/Sys_DirAnzeige.jsp, or (2) list sensitive Jobs via a direct req... Read more
Affected Products : business_manager- Published: Feb. 23, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2009-2171
Mahara 1.1 before 1.1.5 does not apply permission checks when saving a view that contains artefacts, which allows remote authenticated users to read another user's artefact.... Read more
Affected Products : mahara- Published: Jun. 23, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2009-1289
private/login.ssi in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allows remote attackers to discover the access roles and scopes of arbitrary user accounts via a modified WEBINDEX parameter.... Read more
- Published: Apr. 13, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2009-1264
Frontend User Registration (sr_feuser_register) extension 2.5.20 and earlier for TYPO3 does not properly verify access rights, which allows remote authenticated users to obtain sensitive information such as passwords via unknown attack vectors.... Read more
- Published: Apr. 07, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2009-1668
TYPSoft FTP Server 1.11 allows remote attackers to cause a denial of service (CPU consumption) by sending an ABOR (abort) command without an active file transfer.... Read more
Affected Products : typsoft_ftp_server- Published: May. 18, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2008-7289
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 does not properly handle the simultaneous changing of multiple passwords, which makes it easier for remote authenticated users to cause a denial of service (DB2 daemon deadlock) by makin... Read more
Affected Products : tivoli_directory_server- Published: Apr. 21, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2009-0981
Unspecified vulnerability in the Application Express component in Oracle Database 11.1.0.7 allows remote authenticated users to affect confidentiality, related to APEX. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not ... Read more
- Published: Apr. 15, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2008-7264
The ftp_QUIT function in ftpserver.py in pyftpdlib before 0.5.0 allows remote authenticated users to cause a denial of service (file descriptor exhaustion and daemon outage) by sending a QUIT command during a disallowed data-transfer attempt.... Read more
Affected Products : pyftpdlib- Published: Oct. 19, 2010
- Modified: Apr. 11, 2025