CVE List

Id CVE No. Status Description Phase Votes Comments Actions
29185  CVE-2007-5828  Candidate  ** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in the admin panel in Django 0.96 allows remote attackers to change passwords of arbitrary users via a request to admin/auth/user/1/password/. NOTE: this issue has been disputed by Debian, since product documentation includes a recommendation for a CSRF protection module that is included with the product. However, CVE considers this an issue because the default configuration does not use this module.  Assigned (20071105)  None (candidate not yet proposed)    View
94721  CVE-2016-7901  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.  Assigned (20160909)  None (candidate not yet proposed)    View
29441  CVE-2007-6084  Candidate  SQL injection vulnerability in software-description.php in HotScripts Clone Script allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20071121)  None (candidate not yet proposed)    View
94977  CVE-2016-8157  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160909)  None (candidate not yet proposed)    View
29697  CVE-2007-6340  Candidate  Geert Moernaut LSrunasE 1.0 and Supercrypt 1.0 use the RC4 stream cipher without constructing a unique initialization vector (IV), which makes it easier for local users to obtain cleartext passwords.  Assigned (20071213)  None (candidate not yet proposed)    View

Page 1279 of 20943, showing 5 records out of 104715 total, starting on record 6391, ending on 6395

Actions