CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
43536 | CVE-2010-0952 | Candidate | SQL injection vulnerability in index.php in OneCMS 2.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter in an elite action. | Assigned (20100309) | None (candidate not yet proposed) | View | |
43792 | CVE-2010-1208 | Candidate | Use-after-free vulnerability in the attribute-cloning functionality in the DOM implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via vectors related to deletion of an event attribute node with a nonzero reference count. | Assigned (20100330) | None (candidate not yet proposed) | View | |
44048 | CVE-2010-1464 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in WebAsyst Shop-Script FREE allow remote attackers to inject arbitrary web script or HTML via the (1) currency_id_left, (2) currency_id_right, (3) darkcolor, (4) lightcolor, (5) middlecolor, and (6) w parameters. | Assigned (20100416) | None (candidate not yet proposed) | View | |
44304 | CVE-2010-1720 | Candidate | SQL injection vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the katid parameter in a qpListele action to index.php. | Assigned (20100504) | None (candidate not yet proposed) | View | |
44560 | CVE-2010-1976 | Candidate | Cross-site scripting (XSS) vulnerability in the Taxonomy Breadcrumb module 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via the node title in a Breadcrumb display. | Assigned (20100519) | None (candidate not yet proposed) | View |
Page 1336 of 20943, showing 5 records out of 104715 total, starting on record 6676, ending on 6680