CVE List

Id CVE No. Status Description Phase Votes Comments Actions
76050  CVE-2014-8749  Candidate  Server-side request forgery (SSRF) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote attackers to trigger outbound requests that authenticate to arbitrary databases via the dbhost parameter.  Assigned (20141013)  None (candidate not yet proposed)    View
10770  CVE-2004-2344  Candidate  Unknown vulnerability in the ASN.1/H.323/H.225 stack of VocalTec VGW120 and VGW480 allows remote attackers to cause a denial of service.  Assigned (20050816)  None (candidate not yet proposed)    View
76306  CVE-2014-9005  Candidate  Multiple SQL injection vulnerabilities in vldPersonals before 2.7.1 allow remote attackers to execute arbitrary SQL commands via the (1) country, (2) gender1, or ((3) gender2 parameter in a search action to index.php.  Assigned (20141119)  None (candidate not yet proposed)    View
11026  CVE-2004-2600  Candidate  The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter, which allows remote attackers to obtain sensitive information when LAN management functionality is enabled.  Assigned (20051129)  None (candidate not yet proposed)    View
76562  CVE-2014-9261  Candidate  The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to index.php.  Assigned (20141204)  None (candidate not yet proposed)    View

Page 1436 of 20943, showing 5 records out of 104715 total, starting on record 7176, ending on 7180

Actions