CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
36882 | CVE-2008-6765 | Candidate | ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to access the contents of an arbitrary shopping cart via a modified cart_name parameter. | Assigned (20090428) | None (candidate not yet proposed) | View | |
102418 | CVE-2017-5598 | Candidate | An issue was discovered in eClinicalWorks healow@work 8.0 build 8. This is a blind SQL injection within the EmployeePortalServlet, which can be exploited by un-authenticated users via an HTTP POST request and which can be used to dump database data out to a malicious server, using an out-of-band technique, such as select_loadfile(). The vulnerability affects the EmployeePortalServlet page and the following parameter: employer. | Assigned (20170127) | None (candidate not yet proposed) | View | |
37138 | CVE-2008-7021 | Candidate | Unrestricted file upload vulnerability in editlogo.php in AvailScript Jobs Portal Script allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as an image or logo, then accessing it via a direct request to the file in an unspecified directory. | Assigned (20090821) | None (candidate not yet proposed) | View | |
102674 | CVE-2017-5854 | Candidate | base/PdfOutputStream.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file. | Assigned (20170201) | None (candidate not yet proposed) | View | |
37394 | CVE-2008-7277 | Candidate | Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permission, instead of the configured merge permission, during authorization of merge operations, which might allow remote authenticated users to bypass intended access restrictions by merging two tickets. | Assigned (20110318) | None (candidate not yet proposed) | View |
Page 1477 of 20943, showing 5 records out of 104715 total, starting on record 7381, ending on 7385