CVE List

Id CVE No. Status Description Phase Votes Comments Actions
39698  CVE-2009-2263  Candidate  Directory traversal vulnerability in index.php in Awesome PHP Mega File Manager 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.  Assigned (20090629)  None (candidate not yet proposed)    View
39954  CVE-2009-2519  Candidate  The DHTML Editing Component ActiveX control in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly format HTML markup, which allows remote attackers to execute arbitrary code via a crafted web site that triggers "system state" corruption, aka "DHTML Editing Component ActiveX Control Vulnerability."  Assigned (20090717)  None (candidate not yet proposed)    View
40210  CVE-2009-2775  Candidate  SQL injection vulnerability in linkout.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20090814)  None (candidate not yet proposed)    View
40466  CVE-2009-3031  Candidate  Stack-based buffer overflow in the BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control 6.0.0.1846 in AeXNSConsoleUtilities.dll in Symantec Altiris Notification Server (NS) 6.0 before R12, Deployment Server 6.8 and 6.9 in Symantec Altiris Deployment Solution 6.9 SP3, and Symantec Management Platform (SMP) 7.0 before SP3 allows remote attackers to execute arbitrary code via a long string in the second argument.  Assigned (20090831)  None (candidate not yet proposed)    View
40722  CVE-2009-3287  Candidate  lib/thin/connection.rb in Thin web server before 1.2.4 relies on the X-Forwarded-For header to determine the IP address of the client, which allows remote attackers to spoof the IP address and hide activities via a modified X-Forwarded-For header.  Assigned (20090922)  None (candidate not yet proposed)    View

Page 1481 of 20943, showing 5 records out of 104715 total, starting on record 7401, ending on 7405

Actions