CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
76047 | CVE-2014-8746 | Candidate | Cross-site scripting (XSS) vulnerability in the Skeleton theme 7.x-1.2 through 7.x-1.3 before 7.x-1.4, for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to theme settings. | Assigned (20141013) | None (candidate not yet proposed) | View | |
10767 | CVE-2004-2341 | Candidate | PHP file include injection vulnerability in isearch.inc.php for iSearch allows remote attackers to execute arbitrary code via the isearch_path parameter. | Assigned (20050816) | None (candidate not yet proposed) | View | |
76303 | CVE-2014-9002 | Candidate | Lantronix xPrintServer does not properly restrict access to ips/, which allows remote attackers to execute arbitrary commands via the c parameter in an rpc action. | Assigned (20141119) | None (candidate not yet proposed) | View | |
11023 | CVE-2004-2597 | Candidate | Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rules via a userinfo string that already contains an "ip" key/value pair but is also long enough to cause a new key/value pair to be truncated, which interferes with the server"s ability to find the client"s IP address. | Assigned (20051129) | None (candidate not yet proposed) | View | |
76559 | CVE-2014-9258 | Candidate | SQL injection vulnerability in ajax/getDropdownValue.php in GLPI before 0.85.1 allows remote authenticated users to execute arbitrary SQL commands via the condition parameter. | Assigned (20141204) | None (candidate not yet proposed) | View |
Page 1205 of 20943, showing 5 records out of 104715 total, starting on record 6021, ending on 6025