CVE List

Id CVE No. Status Description Phase Votes Comments Actions
43536  CVE-2010-0952  Candidate  SQL injection vulnerability in index.php in OneCMS 2.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter in an elite action.  Assigned (20100309)  None (candidate not yet proposed)    View
43792  CVE-2010-1208  Candidate  Use-after-free vulnerability in the attribute-cloning functionality in the DOM implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via vectors related to deletion of an event attribute node with a nonzero reference count.  Assigned (20100330)  None (candidate not yet proposed)    View
44048  CVE-2010-1464  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in WebAsyst Shop-Script FREE allow remote attackers to inject arbitrary web script or HTML via the (1) currency_id_left, (2) currency_id_right, (3) darkcolor, (4) lightcolor, (5) middlecolor, and (6) w parameters.  Assigned (20100416)  None (candidate not yet proposed)    View
44304  CVE-2010-1720  Candidate  SQL injection vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the katid parameter in a qpListele action to index.php.  Assigned (20100504)  None (candidate not yet proposed)    View
44560  CVE-2010-1976  Candidate  Cross-site scripting (XSS) vulnerability in the Taxonomy Breadcrumb module 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via the node title in a Breadcrumb display.  Assigned (20100519)  None (candidate not yet proposed)    View

Page 1336 of 20943, showing 5 records out of 104715 total, starting on record 6676, ending on 6680

Actions