CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
104210 | CVE-2017-7390 | Candidate | A Cross-Site Scripting (XSS) was discovered in "SocialNetwork v1.2.1". The vulnerability exists due to insufficient filtration of user-supplied data (mail) passed to the "SocialNetwork-andrea/app/template/pw_forgot.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. | Assigned (20170331) | None (candidate not yet proposed) | View | |
38930 | CVE-2009-1495 | Candidate | Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/db.mdb. | Assigned (20090501) | None (candidate not yet proposed) | View | |
104466 | CVE-2017-7646 | Candidate | SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to browse the server"s filesystem and read the contents of arbitrary files contained within. | Assigned (20170410) | None (candidate not yet proposed) | View | |
39186 | CVE-2009-1751 | Candidate | SQL injection vulnerability in list_list.php in Realty Webware Technologies Web-Base 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Assigned (20090521) | None (candidate not yet proposed) | View | |
39442 | CVE-2009-2007 | Candidate | Multiple directory traversal vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to (1) read portions of arbitrary files via a .. (dot dot) and a .. (dot dot backslash) in the lang parameter to main/exercice/hotspot_lang_conversion.php and (2) read arbitrary files via a .. (dot dot) in the doc_url parameter to main/exercice/Hpdownload.php. | Assigned (20090608) | None (candidate not yet proposed) | View |
Page 1480 of 20943, showing 5 records out of 104715 total, starting on record 7396, ending on 7400