CVE List

Id CVE No. Status Description Phase Votes Comments Actions
46863  CVE-2010-4279  Candidate  The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a request to index.php with "admin" in the loginhash_user parameter, in conjunction with the md5 hash of "admin" in the loginhash_data parameter.  Assigned (20101117)  None (candidate not yet proposed)    View
47119  CVE-2010-4535  Candidate  The password reset functionality in django.contrib.auth in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not validate the length of a string representing a base36 timestamp, which allows remote attackers to cause a denial of service (resource consumption) via a URL that specifies a large base36 integer.  Assigned (20101209)  None (candidate not yet proposed)    View
47375  CVE-2010-4791  Candidate  SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user_fotoalbum_panel) module 1.0.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the album_id parameter.  Assigned (20110426)  None (candidate not yet proposed)    View
47631  CVE-2010-5047  Candidate  SQL injection vulnerability in page.php in V-EVA Press Release Script allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20111122)  None (candidate not yet proposed)    View
47887  CVE-2010-5303  Candidate  Cross-site scripting (XSS) vulnerability in the displayError function in timthumb.php in TimThumb before 1.15 (r85), as used in multiple products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to $errorString.  Assigned (20140821)  None (candidate not yet proposed)    View

Page 1260 of 20943, showing 5 records out of 104715 total, starting on record 6296, ending on 6300

Actions