CVE List

Id CVE No. Status Description Phase Votes Comments Actions
15120  CVE-2005-3916  Candidate  SQL injection vulnerability in memberlist.php in WSN Forum 1.21 allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action.  Assigned (20051130)  None (candidate not yet proposed)    View
80656  CVE-2015-3379  Candidate  The Views module before 6.x-2.18, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to the default views configurations, which allows remote authenticated users to obtain sensitive information via unspecified vectors.  Assigned (20150421)  None (candidate not yet proposed)    View
15376  CVE-2005-4172  Candidate  eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information via a direct request to storyblock.php without arguments, which leaks the full pathname in the resulting PHP error message.  Assigned (20051211)  None (candidate not yet proposed)    View
80912  CVE-2015-3635  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150502)  None (candidate not yet proposed)    View
15632  CVE-2005-4428  Candidate  Cross-site scripting (XSS) vulnerability in index.php in Cerberus Helpdesk allows remote attackers to inject arbitrary web script or HTML via the kb_ask parameter.  Assigned (20051220)  None (candidate not yet proposed)    View

Page 1295 of 20943, showing 5 records out of 104715 total, starting on record 6471, ending on 6475

Actions