CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
76050 | CVE-2014-8749 | Candidate | Server-side request forgery (SSRF) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote attackers to trigger outbound requests that authenticate to arbitrary databases via the dbhost parameter. | Assigned (20141013) | None (candidate not yet proposed) | View | |
10770 | CVE-2004-2344 | Candidate | Unknown vulnerability in the ASN.1/H.323/H.225 stack of VocalTec VGW120 and VGW480 allows remote attackers to cause a denial of service. | Assigned (20050816) | None (candidate not yet proposed) | View | |
76306 | CVE-2014-9005 | Candidate | Multiple SQL injection vulnerabilities in vldPersonals before 2.7.1 allow remote attackers to execute arbitrary SQL commands via the (1) country, (2) gender1, or ((3) gender2 parameter in a search action to index.php. | Assigned (20141119) | None (candidate not yet proposed) | View | |
11026 | CVE-2004-2600 | Candidate | The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter, which allows remote attackers to obtain sensitive information when LAN management functionality is enabled. | Assigned (20051129) | None (candidate not yet proposed) | View | |
76562 | CVE-2014-9261 | Candidate | The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to index.php. | Assigned (20141204) | None (candidate not yet proposed) | View |
Page 1436 of 20943, showing 5 records out of 104715 total, starting on record 7176, ending on 7180