|
313521
|
- |
|
hostingcontroller
|
hosting_controller
|
Hosting Controller 6.1 Hotfix 1.9 and earlier allows remote attackers to register arbitrary users via a direct request to addsubsite.asp with the loginname and password parameters set.
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2005-1654
|
2024-01-26 06:03 |
2005-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313522
|
- |
|
yusasp
|
web_asset_manager
|
YusASP Web Asset Manager 1.0 allows remote attackers to gain privileges via a direct request to assetmanager.asp.
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2005-1668
|
2024-01-26 06:03 |
2005-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313523
|
7.5 |
HIGH
Network
|
iomega
|
nas_a300u_firmware
|
The Network Attached Storage (NAS) Administration Web Page for Iomega NAS A300U transmits passwords in cleartext, which allows remote attackers to sniff the administrative password.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2002-1949
|
2024-01-26 06:00 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313524
|
7.5 |
HIGH
Network
|
procom
|
netforce_800_firmware
|
Procom NetFORCE 800 4.02 M10 Build 20 and possibly other versions sends the NIS password map (passwd.nis) as a file attachment in diagnostic e-mail messages, which allows remote attackers to obtain t…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2005-3140
|
2024-01-26 05:58 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313525
|
- |
|
solarwinds
|
dameware_mini_remote_control
|
DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to gain sensitive information.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2004-1852
|
2024-01-26 05:57 |
2004-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313526
|
5.5 |
MEDIUM
Local
|
macromedia
|
coldfusion
|
ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to access trusted Java objects without usin…
|
CWE-470
Unsafe Reflection
|
CVE-2004-2331
|
2024-01-25 11:16 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313527
|
9.8 |
CRITICAL
Network
|
mozilla sco
|
mozilla openserver
|
The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, whic…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2003-0791
|
2024-01-25 11:14 |
2003-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313528
|
- |
|
-
|
-
|
Rejected reason: ** REJECT **
DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-5533. Reason: This record is a reservation duplicate of CVE-2023-5533. Notes: All CVE users should reference CVE-2023-55…
|
-
|
CVE-2023-5656
|
2024-01-24 08:15 |
2023-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313529
|
- |
|
-
|
-
|
Rejected reason: ** REJECT **
DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-5534. Reason: This record is a reservation duplicate of CVE-2023-5534. Notes: All CVE users should reference CVE-2023-55…
|
-
|
CVE-2023-5655
|
2024-01-24 08:15 |
2023-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313530
|
- |
|
-
|
-
|
Rejected reason: ** REJECT **
DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-5212. Reason: This record is a reservation duplicate of CVE-2023-5212. Notes: All CVE users should reference CVE-2023-52…
|
-
|
CVE-2023-5647
|
2024-01-24 08:15 |
2023-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|