CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
69135 | CVE-2014-1840 | Candidate | Cross-site scripting (XSS) vulnerability in Upload/search.php in MyBB 1.6.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a do_search action, which is not properly handled in a forced SQL error message. | Assigned (20140202) | None (candidate not yet proposed) | View | |
3855 | CVE-2001-1051 | Candidate | Dark Hart Portal (darkportal) PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. | Proposed (20020131) | ACCEPT(2) Frech, Green | NOOP(3) Cole, Foat, Wall | View | |
69391 | CVE-2014-2096 | Candidate | Untrusted search path vulnerability in Catfish 0.6.0 through 1.0.0 allows local users to gain privileges via a Trojan horse bin/catfish.py under the current working directory. | Assigned (20140224) | None (candidate not yet proposed) | View | |
4111 | CVE-2001-1307 | Candidate | Buffer overflows in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite. | Proposed (20020502) | ACCEPT(4) Cole, Frech, Green, Wall | NOOP(2) Cox, Foat | View | |
69647 | CVE-2014-2352 | Candidate | Directory traversal vulnerability in Cogent DataHub before 7.3.5 allows remote attackers to read arbitrary files of unspecified types, or cause a web-server denial of service, via a crafted pathname. | Assigned (20140313) | None (candidate not yet proposed) | View |
Page 1199 of 20943, showing 5 records out of 104715 total, starting on record 5991, ending on 5995