CVE List

Id CVE No. Status Description Phase Votes Comments Actions
36882  CVE-2008-6765  Candidate  ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to access the contents of an arbitrary shopping cart via a modified cart_name parameter.  Assigned (20090428)  None (candidate not yet proposed)    View
102418  CVE-2017-5598  Candidate  An issue was discovered in eClinicalWorks healow@work 8.0 build 8. This is a blind SQL injection within the EmployeePortalServlet, which can be exploited by un-authenticated users via an HTTP POST request and which can be used to dump database data out to a malicious server, using an out-of-band technique, such as select_loadfile(). The vulnerability affects the EmployeePortalServlet page and the following parameter: employer.  Assigned (20170127)  None (candidate not yet proposed)    View
37138  CVE-2008-7021  Candidate  Unrestricted file upload vulnerability in editlogo.php in AvailScript Jobs Portal Script allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as an image or logo, then accessing it via a direct request to the file in an unspecified directory.  Assigned (20090821)  None (candidate not yet proposed)    View
102674  CVE-2017-5854  Candidate  base/PdfOutputStream.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.  Assigned (20170201)  None (candidate not yet proposed)    View
37394  CVE-2008-7277  Candidate  Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permission, instead of the configured merge permission, during authorization of merge operations, which might allow remote authenticated users to bypass intended access restrictions by merging two tickets.  Assigned (20110318)  None (candidate not yet proposed)    View

Page 1477 of 20943, showing 5 records out of 104715 total, starting on record 7381, ending on 7385

Actions