CVE List

Id CVE No. Status Description Phase Votes Comments Actions
41998  CVE-2009-4563  Candidate  Cross-site request forgery (CSRF) vulnerability in zp-core/admin-options.php in Zenphoto 1.2.5 allows remote attackers to hijack the authentication of administrators for requests that change the administrative password via the 0-adminpass and 0-adminpass_2 parameters in a saveoptions action.  Assigned (20100104)  None (candidate not yet proposed)    View
42254  CVE-2009-4819  Candidate  Multiple unrestricted file upload vulnerabilities in upload.php in PHPhotoalbum allow remote attackers to execute arbitrary code by uploading a file with a (1) .php.pgif or (2) .php.pjpeg double extension, then accessing it via a direct request to the file in albums/userpics/.  Assigned (20100427)  None (candidate not yet proposed)    View
42510  CVE-2009-5075  Candidate  Monkey"s Audio before 4.02 allows remote attackers to cause a denial of service (application crash) via a malformed APE file.  Assigned (20110520)  None (candidate not yet proposed)    View
42766  CVE-2010-0182  Candidate  The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 does not perform the expected nsIContentPolicy checks during loading of content by XML documents, which allows attackers to bypass intended access restrictions via crafted content.  Assigned (20100106)  None (candidate not yet proposed)    View
43022  CVE-2010-0438  Candidate  Multiple SQL injection vulnerabilities in Kernel/System/Ticket.pm in OTRS-Core in Open Ticket Request System (OTRS) 2.1.x before 2.1.9, 2.2.x before 2.2.9, 2.3.x before 2.3.5, and 2.4.x before 2.4.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.  Assigned (20100127)  None (candidate not yet proposed)    View

Page 1177 of 20943, showing 5 records out of 104715 total, starting on record 5881, ending on 5885

Actions