CVE List

Id CVE No. Status Description Phase Votes Comments Actions
43023  CVE-2010-0439  Candidate  Chip Salzenberg Deliver allows local users to cause a denial of service, obtain sensitive information, and possibly change the ownership of arbitrary files via a symlink attack on an unspecified file.  Assigned (20100127)  None (candidate not yet proposed)    View
43279  CVE-2010-0695  Candidate  Cross-site scripting (XSS) vulnerability in pages/index.php in BASIC-CMS allows remote attackers to inject arbitrary web script or HTML via the nav_id parameter.  Assigned (20100223)  None (candidate not yet proposed)    View
43535  CVE-2010-0951  Candidate  SQL injection vulnerability in go_target.php in dev4u CMS allows remote attackers to execute arbitrary SQL commands via the kontent_id parameter.  Assigned (20100309)  None (candidate not yet proposed)    View
43791  CVE-2010-1207  Candidate  Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 do not properly implement read restrictions for CANVAS elements, which allows remote attackers to obtain sensitive cross-origin information via vectors involving reference retention and node deletion.  Assigned (20100330)  None (candidate not yet proposed)    View
44047  CVE-2010-1463  Candidate  Multiple SQL injection vulnerabilities in WebAsyst Shop-Script FREE allow attackers to execute arbitrary SQL commands via the (1) add2cart, (2) c_id, (3) categoryID, (4) list_price, (5) name, (6) new_offer, (7) price, (8) product_code, (9) productID, (10) rating, and (11) save_product parameters.  Assigned (20100416)  None (candidate not yet proposed)    View

Page 1257 of 20943, showing 5 records out of 104715 total, starting on record 6281, ending on 6285

Actions