CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93441  CVE-2016-6621  Candidate  The setup script for phpMyAdmin before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.  Assigned (20160806)  None (candidate not yet proposed)    View
28161  CVE-2007-4804  Candidate  Multiple SQL injection vulnerabilities in AuraCMS 1.5rc allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) hal.php, (2) cetak.php, (3) lihat.php, (4) pesan.php, and (5) teman.php, different vectors than CVE-2007-4171. NOTE: the scripts may be accessed through requests to the product"s top-level default URI, using the pilih parameter, in some circumstances.  Assigned (20070911)  None (candidate not yet proposed)    View
93697  CVE-2016-6877  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160818)  None (candidate not yet proposed)    View
28417  CVE-2007-5060  Candidate  Cross-site request forgery (CSRF) vulnerability in the cpass functionality in an admin action in index.php in XCMS allows remote attackers to change arbitrary passwords via certain password_ and rpassword_ parameters, possibly related to timestamp values.  Assigned (20070924)  None (candidate not yet proposed)    View
93953  CVE-2016-7133  Candidate  Zend/zend_alloc.c in PHP 7.x before 7.0.10, when open_basedir is enabled, mishandles huge realloc operations, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a long pathname.  Assigned (20160902)  None (candidate not yet proposed)    View

Page 122 of 20943, showing 5 records out of 104715 total, starting on record 606, ending on 610

Actions