CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
47375 | CVE-2010-4791 | Candidate | SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user_fotoalbum_panel) module 1.0.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the album_id parameter. | Assigned (20110426) | None (candidate not yet proposed) | View | |
47631 | CVE-2010-5047 | Candidate | SQL injection vulnerability in page.php in V-EVA Press Release Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | Assigned (20111122) | None (candidate not yet proposed) | View | |
47887 | CVE-2010-5303 | Candidate | Cross-site scripting (XSS) vulnerability in the displayError function in timthumb.php in TimThumb before 1.15 (r85), as used in multiple products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to $errorString. | Assigned (20140821) | None (candidate not yet proposed) | View | |
48143 | CVE-2011-0231 | Candidate | CFNetwork in Apple Mac OS X before 10.7.2 does not properly follow an intended cookie-storage policy, which makes it easier for remote web servers to track users via a cookie, related to a "synchronization issue." | Assigned (20101223) | None (candidate not yet proposed) | View | |
48399 | CVE-2011-0487 | Candidate | ICQ 7 does not verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a crafted file that is fetched through an automatic-update mechanism. | Assigned (20110118) | None (candidate not yet proposed) | View |
Page 1256 of 20943, showing 5 records out of 104715 total, starting on record 6276, ending on 6280