CVE List

Id CVE No. Status Description Phase Votes Comments Actions
36879  CVE-2008-6762  Candidate  Open redirect vulnerability in wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backto parameter.  Assigned (20090428)  None (candidate not yet proposed)    View
102415  CVE-2017-5595  Candidate  A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being passed to readfile(), which allows an authenticated attacker to read local system files (e.g., /etc/passwd) in the context of the web server user (www-data). The attack vector is a .. (dot dot) in the path parameter within a zm/index.php?view=file&path= request.  Assigned (20170125)  None (candidate not yet proposed)    View
37135  CVE-2008-7018  Candidate  Cross-site scripting (XSS) vulnerability in NashTech Easy PHP Calendar 6.3.25 allows remote attackers to inject arbitrary web script or HTML via the Details field (descr parameter) in an Add New Event action in an unspecified request as generated by an add action in index.php.  Assigned (20090821)  None (candidate not yet proposed)    View
102671  CVE-2017-5851  Candidate  The free_options function in options_manager.c in mp3splt 2.6.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file. NOTE: this typically has no risk; this crash of this command-line program has no further consequences for availability.  Assigned (20170201)  None (candidate not yet proposed)    View
37391  CVE-2008-7274  Candidate  IBM WebSphere Application Server (WAS) 6.1.0.9, when the JAAS Login functionality is enabled, allows attackers to perform an internal application hashtable login by (1) not providing a password or (2) providing an empty password.  Assigned (20110214)  None (candidate not yet proposed)    View

Page 1246 of 20943, showing 5 records out of 104715 total, starting on record 6226, ending on 6230

Actions