CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
36623 | CVE-2008-6506 | Candidate | Unspecified vulnerability in phpBB before 3.0.4 allows attackers to bypass intended access restrictions and activate de-activated accounts via unknown vectors. | Assigned (20090323) | None (candidate not yet proposed) | View | |
102159 | CVE-2017-5339 | Candidate | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. | Assigned (20170110) | None (candidate not yet proposed) | View | |
36879 | CVE-2008-6762 | Candidate | Open redirect vulnerability in wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backto parameter. | Assigned (20090428) | None (candidate not yet proposed) | View | |
102415 | CVE-2017-5595 | Candidate | A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being passed to readfile(), which allows an authenticated attacker to read local system files (e.g., /etc/passwd) in the context of the web server user (www-data). The attack vector is a .. (dot dot) in the path parameter within a zm/index.php?view=file&path= request. | Assigned (20170125) | None (candidate not yet proposed) | View | |
37135 | CVE-2008-7018 | Candidate | Cross-site scripting (XSS) vulnerability in NashTech Easy PHP Calendar 6.3.25 allows remote attackers to inject arbitrary web script or HTML via the Details field (descr parameter) in an Add New Event action in an unspecified request as generated by an add action in index.php. | Assigned (20090821) | None (candidate not yet proposed) | View |
Page 1250 of 20943, showing 5 records out of 104715 total, starting on record 6246, ending on 6250