CVE List

Id CVE No. Status Description Phase Votes Comments Actions
46608  CVE-2010-4024  Candidate  Cross-site request forgery (CSRF) vulnerability in HP Insight Control Power Management before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.  Assigned (20101021)  None (candidate not yet proposed)    View
46864  CVE-2010-4280  Candidate  Multiple SQL injection vulnerabilities in Pandora FMS before 3.1.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the id_group parameter in an operation/agentes/ver_agente action to ajax.php or (2) the group_id parameter in an operation/agentes/estado_agente action to index.php, related to operation/agentes/estado_agente.php.  Assigned (20101117)  None (candidate not yet proposed)    View
47120  CVE-2010-4536  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the & (ampersand) character, (2) the case of an attribute name, (3) a padded entity, and (4) an entity that is not in normalized form.  Assigned (20101209)  None (candidate not yet proposed)    View
47376  CVE-2010-4792  Candidate  Cross-site scripting (XSS) vulnerability in title.php in OPEN IT OverLook 5.0 allows remote attackers to inject arbitrary web script or HTML via the frame parameter.  Assigned (20110426)  None (candidate not yet proposed)    View
47632  CVE-2010-5048  Candidate  Cross-site scripting (XSS) vulnerability in admin.jcomments.php in the JoomlaTune JComments (com_jcomments) component 2.1.0.0 for Joomla! allows remote authenticated users to inject arbitrary web script or HTML via the name parameter to index.php.  Assigned (20111122)  None (candidate not yet proposed)    View

Page 1356 of 20943, showing 5 records out of 104715 total, starting on record 6776, ending on 6780

Actions