CVE List

Id CVE No. Status Description Phase Votes Comments Actions
47375  CVE-2010-4791  Candidate  SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user_fotoalbum_panel) module 1.0.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the album_id parameter.  Assigned (20110426)  None (candidate not yet proposed)    View
47631  CVE-2010-5047  Candidate  SQL injection vulnerability in page.php in V-EVA Press Release Script allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20111122)  None (candidate not yet proposed)    View
47887  CVE-2010-5303  Candidate  Cross-site scripting (XSS) vulnerability in the displayError function in timthumb.php in TimThumb before 1.15 (r85), as used in multiple products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to $errorString.  Assigned (20140821)  None (candidate not yet proposed)    View
48143  CVE-2011-0231  Candidate  CFNetwork in Apple Mac OS X before 10.7.2 does not properly follow an intended cookie-storage policy, which makes it easier for remote web servers to track users via a cookie, related to a "synchronization issue."  Assigned (20101223)  None (candidate not yet proposed)    View
48399  CVE-2011-0487  Candidate  ICQ 7 does not verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a crafted file that is fetched through an automatic-update mechanism.  Assigned (20110118)  None (candidate not yet proposed)    View

Page 1256 of 20943, showing 5 records out of 104715 total, starting on record 6276, ending on 6280

Actions