CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
41740 | CVE-2009-4305 | Candidate | SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitrary SQL commands via vectors related to an "escaping issue when processing AICC CRS file (Course_Title)." | Assigned (20091211) | None (candidate not yet proposed) | View | |
41996 | CVE-2009-4561 | Candidate | Multiple SQL injection vulnerabilities in Admin/index.php in WebLeague 2.2.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | Assigned (20100104) | None (candidate not yet proposed) | View | |
42252 | CVE-2009-4817 | Candidate | Unrestricted file upload vulnerability in Element-IT Ultimate Uploader 1.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in upload/. | Assigned (20100427) | None (candidate not yet proposed) | View | |
42508 | CVE-2009-5073 | Candidate | IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.59 (aka 6.0.0.8-TIV-ITDS-IF0001) allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) by adding a nested group that contains the Distinguished Name (DN) of its parent entry. | Assigned (20110420) | None (candidate not yet proposed) | View | |
42764 | CVE-2010-0180 | Candidate | Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when use_suexec is enabled, uses world-readable permissions for the localconfig files, which allows local users to read sensitive configuration fields, as demonstrated by the database password field and the site_wide_secret field. | Assigned (20100106) | None (candidate not yet proposed) | View |
Page 1018 of 20943, showing 5 records out of 104715 total, starting on record 5086, ending on 5090