CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
52481 | CVE-2011-4569 | Candidate | SQL injection vulnerability in userbarsettings.php in the Userbar plugin 2.2 for MyBB Forum allows remote attackers to execute arbitrary SQL commands via the image2 parameter. | Assigned (20111128) | None (candidate not yet proposed) | View | |
52737 | CVE-2011-4825 | Candidate | Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters. | Assigned (20111214) | None (candidate not yet proposed) | View | |
52993 | CVE-2011-5081 | Candidate | Cross-site scripting (XSS) vulnerability in RestoreFile.pm in BackupPC 3.1.0, 3.2.1, and possibly other earlier versions allows remote attackers to inject arbitrary web script or HTML via the share parameter in a RestoreFile action to index.cgi. | Assigned (20120217) | None (candidate not yet proposed) | View | |
53249 | CVE-2012-0006 | Candidate | The DNS server in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 does not properly handle objects in memory during record lookup, which allows remote attackers to cause a denial of service (daemon restart) via a crafted query, aka "DNS Denial of Service Vulnerability." | Assigned (20111109) | None (candidate not yet proposed) | View | |
53505 | CVE-2012-0262 | Candidate | op5config/welcome in system-op5config before 2.0.3 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the password parameter. | Assigned (20111221) | None (candidate not yet proposed) | View |
Page 150 of 20943, showing 5 records out of 104715 total, starting on record 746, ending on 750