CVE List

Id CVE No. Status Description Phase Votes Comments Actions
43538  CVE-2010-0954  Candidate  SQL injection vulnerability in search_result.asp in Pre Projects Pre E-Learning Portal allows remote attackers to execute arbitrary SQL commands via the course_ID parameter.  Assigned (20100309)  None (candidate not yet proposed)    View
43794  CVE-2010-1210  Candidate  intl/uconv/util/nsUnicodeDecodeHelper.cpp in Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 inserts a U+FFFD sequence into text in certain circumstances involving undefined positions, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted 8-bit text.  Assigned (20100330)  None (candidate not yet proposed)    View
44050  CVE-2010-1466  Candidate  Directory traversal vulnerability in scr/soustab.php in openUrgence Vaccin 1.03 allows remote attackers to read arbitrary files via the dsn[phptype] parameter.  Assigned (20100416)  None (candidate not yet proposed)    View
44306  CVE-2010-1722  Candidate  Directory traversal vulnerability in the Online Market (com_market) component 2.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.  Assigned (20100504)  None (candidate not yet proposed)    View
44562  CVE-2010-1978  Candidate  PHP remote file inclusion vulnerability in default_theme.php in FreePHPBlogSoftware 1.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the phpincdir parameter. NOTE: some of these details are obtained from third party information.  Assigned (20100519)  None (candidate not yet proposed)    View

Page 1484 of 20943, showing 5 records out of 104715 total, starting on record 7416, ending on 7420

Actions