CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
41998 | CVE-2009-4563 | Candidate | Cross-site request forgery (CSRF) vulnerability in zp-core/admin-options.php in Zenphoto 1.2.5 allows remote attackers to hijack the authentication of administrators for requests that change the administrative password via the 0-adminpass and 0-adminpass_2 parameters in a saveoptions action. | Assigned (20100104) | None (candidate not yet proposed) | View | |
42254 | CVE-2009-4819 | Candidate | Multiple unrestricted file upload vulnerabilities in upload.php in PHPhotoalbum allow remote attackers to execute arbitrary code by uploading a file with a (1) .php.pgif or (2) .php.pjpeg double extension, then accessing it via a direct request to the file in albums/userpics/. | Assigned (20100427) | None (candidate not yet proposed) | View | |
42510 | CVE-2009-5075 | Candidate | Monkey"s Audio before 4.02 allows remote attackers to cause a denial of service (application crash) via a malformed APE file. | Assigned (20110520) | None (candidate not yet proposed) | View | |
42766 | CVE-2010-0182 | Candidate | The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 does not perform the expected nsIContentPolicy checks during loading of content by XML documents, which allows attackers to bypass intended access restrictions via crafted content. | Assigned (20100106) | None (candidate not yet proposed) | View | |
43022 | CVE-2010-0438 | Candidate | Multiple SQL injection vulnerabilities in Kernel/System/Ticket.pm in OTRS-Core in Open Ticket Request System (OTRS) 2.1.x before 2.1.9, 2.2.x before 2.2.9, 2.3.x before 2.3.5, and 2.4.x before 2.4.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | Assigned (20100127) | None (candidate not yet proposed) | View |
Page 1177 of 20943, showing 5 records out of 104715 total, starting on record 5881, ending on 5885