CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
46607 | CVE-2010-4023 | Candidate | Cross-site scripting (XSS) vulnerability in HP Insight Control Power Management before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20101021) | None (candidate not yet proposed) | View | |
46863 | CVE-2010-4279 | Candidate | The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a request to index.php with "admin" in the loginhash_user parameter, in conjunction with the md5 hash of "admin" in the loginhash_data parameter. | Assigned (20101117) | None (candidate not yet proposed) | View | |
47119 | CVE-2010-4535 | Candidate | The password reset functionality in django.contrib.auth in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not validate the length of a string representing a base36 timestamp, which allows remote attackers to cause a denial of service (resource consumption) via a URL that specifies a large base36 integer. | Assigned (20101209) | None (candidate not yet proposed) | View | |
47375 | CVE-2010-4791 | Candidate | SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user_fotoalbum_panel) module 1.0.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the album_id parameter. | Assigned (20110426) | None (candidate not yet proposed) | View | |
47631 | CVE-2010-5047 | Candidate | SQL injection vulnerability in page.php in V-EVA Press Release Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | Assigned (20111122) | None (candidate not yet proposed) | View |
Page 1275 of 20943, showing 5 records out of 104715 total, starting on record 6371, ending on 6375