CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104210  CVE-2017-7390  Candidate  A Cross-Site Scripting (XSS) was discovered in "SocialNetwork v1.2.1". The vulnerability exists due to insufficient filtration of user-supplied data (mail) passed to the "SocialNetwork-andrea/app/template/pw_forgot.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.  Assigned (20170331)  None (candidate not yet proposed)    View
38930  CVE-2009-1495  Candidate  Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/db.mdb.  Assigned (20090501)  None (candidate not yet proposed)    View
104466  CVE-2017-7646  Candidate  SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to browse the server"s filesystem and read the contents of arbitrary files contained within.  Assigned (20170410)  None (candidate not yet proposed)    View
39186  CVE-2009-1751  Candidate  SQL injection vulnerability in list_list.php in Realty Webware Technologies Web-Base 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20090521)  None (candidate not yet proposed)    View
39442  CVE-2009-2007  Candidate  Multiple directory traversal vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to (1) read portions of arbitrary files via a .. (dot dot) and a .. (dot dot backslash) in the lang parameter to main/exercice/hotspot_lang_conversion.php and (2) read arbitrary files via a .. (dot dot) in the doc_url parameter to main/exercice/Hpdownload.php.  Assigned (20090608)  None (candidate not yet proposed)    View

Page 1480 of 20943, showing 5 records out of 104715 total, starting on record 7396, ending on 7400

Actions