CVE List

Id CVE No. Status Description Phase Votes Comments Actions
35338  CVE-2008-5221  Candidate  The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified password and password_retype parameters.  Assigned (20081125)  None (candidate not yet proposed)    View
100874  CVE-2017-4054  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161226)  None (candidate not yet proposed)    View
35594  CVE-2008-5477  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20081211)  None (candidate not yet proposed)    View
101130  CVE-2017-4310  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161226)  None (candidate not yet proposed)    View
35850  CVE-2008-5733  Candidate  SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20081226)  None (candidate not yet proposed)    View

Page 1463 of 20943, showing 5 records out of 104715 total, starting on record 7311, ending on 7315

Actions