CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
19470 | CVE-2006-3366 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or HTML via crafted HTML tags, as demonstrated by the IMG tag, in the (1) id parameter in (a) mail/index.php and (b) mail/reply.php; (2) login_id parameter in (c) members/is_online.php; (3) site_id parameter in (d) messenger/online.php, (e) messenger/search.php, and (f) messenger/profile.php; (4) contact_name parameter in messenger/search.php; (5) membername parameter in (g) messenger/profileview.php; (6) unspecified parameters used when "editing a profile"; and (7) cust_name parameter in (h) messenger/expire.php. NOTE: The vendor disputes the vectors involving files in the messenger directory, stating "... the referenced folder "messenger" was never available to the general public...". | Assigned (20060706) | None (candidate not yet proposed) | View | |
85006 | CVE-2015-7729 | Candidate | Eval injection in test-net.xsjs in the Web-based Development Workbench in SAP HANA Developer Edition DB 1.00.091.00.1418659308 allows remote authenticated users to execute arbitrary XSJS code via unspecified vectors, aka SAP Security Note 2153892. | Assigned (20151006) | None (candidate not yet proposed) | View | |
19726 | CVE-2006-3622 | Candidate | The showtopic module in Koobi Pro CMS 5.6 allows remote attackers to obtain sensitive information via a " (single quote) in the p parameter, which displays the path in an error message. NOTE: it is not clear whether this is SQL injection or a forced SQL error. | Assigned (20060714) | None (candidate not yet proposed) | View | |
85262 | CVE-2015-7985 | Candidate | Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges via a Trojan horse steam.exe file. | Assigned (20151027) | None (candidate not yet proposed) | View | |
19982 | CVE-2006-3878 | Candidate | Opsware Network Automation System (NAS) 6.0 installs /etc/init.d/mysql with insecure permissions, which allows local users to read the root password for the MySQL MAX database or gain privileges by modifying /etc/init.d/mysql. | Assigned (20060726) | None (candidate not yet proposed) | View |
Page 1144 of 20943, showing 5 records out of 104715 total, starting on record 5716, ending on 5720