CVE List

Id CVE No. Status Description Phase Votes Comments Actions
46607  CVE-2010-4023  Candidate  Cross-site scripting (XSS) vulnerability in HP Insight Control Power Management before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20101021)  None (candidate not yet proposed)    View
46863  CVE-2010-4279  Candidate  The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a request to index.php with "admin" in the loginhash_user parameter, in conjunction with the md5 hash of "admin" in the loginhash_data parameter.  Assigned (20101117)  None (candidate not yet proposed)    View
47119  CVE-2010-4535  Candidate  The password reset functionality in django.contrib.auth in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not validate the length of a string representing a base36 timestamp, which allows remote attackers to cause a denial of service (resource consumption) via a URL that specifies a large base36 integer.  Assigned (20101209)  None (candidate not yet proposed)    View
47375  CVE-2010-4791  Candidate  SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user_fotoalbum_panel) module 1.0.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the album_id parameter.  Assigned (20110426)  None (candidate not yet proposed)    View
47631  CVE-2010-5047  Candidate  SQL injection vulnerability in page.php in V-EVA Press Release Script allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20111122)  None (candidate not yet proposed)    View

Page 1275 of 20943, showing 5 records out of 104715 total, starting on record 6371, ending on 6375

Actions