CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
36366 | CVE-2008-6249 | Candidate | SQL injection vulnerability in plugins/users/index.php in Galatolo WebManager 1.3a and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | Assigned (20090223) | None (candidate not yet proposed) | View | |
101902 | CVE-2017-5082 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170102) | None (candidate not yet proposed) | View | |
36622 | CVE-2008-6505 | Candidate | Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary files via a ..%252f (encoded dot dot slash) in a URI with a /struts/ path, related to (1) FilterDispatcher in 2.0.x and (2) DefaultStaticContentLoader in 2.1.x. | Assigned (20090323) | None (candidate not yet proposed) | View | |
102158 | CVE-2017-5338 | Candidate | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. | Assigned (20170110) | None (candidate not yet proposed) | View | |
36878 | CVE-2008-6761 | Candidate | Static code injection vulnerability in admin/install.php in Flexcustomer 0.0.6 might allow remote attackers to inject arbitrary PHP code into const.inc.php via the installdbname parameter (aka the Database Name field). NOTE: the installation instructions specify deleting admin/install.php. | Assigned (20090428) | None (candidate not yet proposed) | View |
Page 1184 of 20943, showing 5 records out of 104715 total, starting on record 5916, ending on 5920