CVE List

Id CVE No. Status Description Phase Votes Comments Actions
73489  CVE-2014-6190  Candidate  The log viewer in IBM Workload Deployer 3.1 before 3.1.0.7 allows remote attackers to obtain sensitive information via a direct request for the URL of a log document.  Assigned (20140902)  None (candidate not yet proposed)    View
8209  CVE-2003-1385  Candidate  ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code.  Assigned (20071018)  None (candidate not yet proposed)    View
73745  CVE-2014-6445  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in includes/toAdmin.php in Contact Form 7 Integrations plugin 1.0 through 1.3.10 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) uE or (2) uC parameter.  Assigned (20140916)  None (candidate not yet proposed)    View
74001  CVE-2014-6701  Candidate  The Vendormate Mobile (aka com.vendormate.mobile) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140919)  None (candidate not yet proposed)    View
8721  CVE-2004-0293  Candidate  Directory traversal vulnerability in ShopCartCGI 2.3 allows remote attackers to retrieve arbitrary files via a .. (dot dot) in a HTTP request to (1) gotopage.cgi or (2) genindexpage.cgi.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View

Page 1382 of 20943, showing 5 records out of 104715 total, starting on record 6906, ending on 6910

Actions