CVE List

Id CVE No. Status Description Phase Votes Comments Actions
76047  CVE-2014-8746  Candidate  Cross-site scripting (XSS) vulnerability in the Skeleton theme 7.x-1.2 through 7.x-1.3 before 7.x-1.4, for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to theme settings.  Assigned (20141013)  None (candidate not yet proposed)    View
10767  CVE-2004-2341  Candidate  PHP file include injection vulnerability in isearch.inc.php for iSearch allows remote attackers to execute arbitrary code via the isearch_path parameter.  Assigned (20050816)  None (candidate not yet proposed)    View
76303  CVE-2014-9002  Candidate  Lantronix xPrintServer does not properly restrict access to ips/, which allows remote attackers to execute arbitrary commands via the c parameter in an rpc action.  Assigned (20141119)  None (candidate not yet proposed)    View
11023  CVE-2004-2597  Candidate  Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rules via a userinfo string that already contains an "ip" key/value pair but is also long enough to cause a new key/value pair to be truncated, which interferes with the server"s ability to find the client"s IP address.  Assigned (20051129)  None (candidate not yet proposed)    View
76559  CVE-2014-9258  Candidate  SQL injection vulnerability in ajax/getDropdownValue.php in GLPI before 0.85.1 allows remote authenticated users to execute arbitrary SQL commands via the condition parameter.  Assigned (20141204)  None (candidate not yet proposed)    View

Page 1205 of 20943, showing 5 records out of 104715 total, starting on record 6021, ending on 6025

Actions