Skip to main content

CWE archive

CWE-255 CVEs

Programmatic archive

780 CVEs tagged with CWE-255196 Critical, 163 High, 307 Medium, 114 Low, 0 Unrated.

CVE-2007-6414

Published Dec 17, 2007

admin/administrator.php in Adult Script 1.6 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to bypass authentication and obtain ad…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6399

Published Dec 17, 2007

index.php in Flat PHP Board 1.2 and earlier allows remote authenticated users to obtain the password for the current user account by reading the password parameter value in the HT…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6329

Published Dec 13, 2007

Microsoft Office 2007 12.0.6015.5000 and MSO 12.0.6017.5000 do not sign the metadata of Office Open XML (OOXML) documents, which makes it easier for remote attackers to modify Dub…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6260

Published Dec 6, 2007

The installation process for Oracle 10g and llg uses accounts with default passwords, which allows remote attackers to obtain login access by connecting to the Listener. NOTE: at…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5905

Published Nov 15, 2007

Adobe ColdFusion 8 and MX 7 allows remote attackers to hijack sessions via unspecified vectors that trigger establishment of a session to a ColdFusion application in which the (1)…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5988

Published Nov 15, 2007

blocks/shoutbox_block.php in BtiTracker 1.4.4 does not verify user accounts, which allows remote attackers to post shoutbox entries as arbitrary users via a modified nick field.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4994

Published Nov 6, 2007

Certificate Server 7.2 in Red Hat Certificate System (RHCS) does not properly handle new revocations that occur while a Certificate Revocation List (CRL) is being generated, which…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5579

Published Oct 18, 2007

login.php in Pligg CMS 9.5 uses a guessable confirmation code when resetting a forgotten password, which allows remote attackers with knowledge of a username to reset that user's…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5063

Published Sep 24, 2007

Adam Scheinberg Flip 3.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4960

Published Sep 18, 2007

Argument injection vulnerability in the Linden Lab Second Life secondlife:// protocol handler, as used in Internet Explorer and possibly Firefox, allows remote attackers to obtain…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4598

Published Aug 30, 2007

IBM SurePOS 500 has (1) a default password of "12345" for the manager and (2) blank default passwords for operator accounts.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4594

Published Aug 29, 2007

Entrust Entelligence Security Provider (ESP) 8 does not properly validate certificates in certain circumstances involving (1) a chain that omits the root Certification Authority (…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4261

Published Aug 8, 2007

EZPhotoSales 1.9.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download (1) a file containing cl…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3978

Published Jul 25, 2007

Session fixation vulnerability in bwired allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3275

Published Jun 19, 2007

MailWasher Server before 2.2.1, when used with LDAP or Active Directory (AD), does not properly handle blank passwords, which allows remote attackers to access an arbitrary user a…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3061

Published Jun 6, 2007

Cactushop 6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-2766

Published May 18, 2007

lib/backup-methods.sh in Backup Manager before 0.7.6 provides the MySQL password as a plaintext command line argument, which allows local users to obtain this password by listing…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4068

Published Aug 10, 2006

The pswd.js script relies on the client to calculate whether a username and password match hard-coded hashed values for a server, and uses a hashing scheme that creates a large nu…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 726-750 of 780 CVEsPage 30 of 32