CVE List

Id CVE No. Status Description Phase Votes Comments Actions
30468  CVE-2008-0351  Candidate  admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es_security_captcha parameter and not invoking captcha.php.  Assigned (20080117)  None (candidate not yet proposed)    View
96004  CVE-2016-9184  Candidate  In /framework/modules/core/controllers/expHTMLEditorController.php of Exponent CMS 2.4.0, untrusted input is used to construct a table name, and in the selectObject method in mysqli class, table names are wrapped with a character that common filters do not filter, allowing for SQL Injection. Impact is Information Disclosure.  Assigned (20161104)  None (candidate not yet proposed)    View
30724  CVE-2008-0607  Candidate  SQL injection vulnerability in index.php in the Sigsiu Online Business Index 2 (SOBI2, com_sobi2) 2.5.3 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20080205)  None (candidate not yet proposed)    View
96260  CVE-2016-9440  Candidate  An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.  Assigned (20161118)  None (candidate not yet proposed)    View
30980  CVE-2008-0863  Candidate  BEA WebLogic Server and WebLogic Express 9.0 and 9.1 exposes the web service"s WSDL and security policies, which allows remote attackers to obtain sensitive information and potentially launch further attacks.  Assigned (20080220)  None (candidate not yet proposed)    View

Page 1513 of 20943, showing 5 records out of 104715 total, starting on record 7561, ending on 7565

Actions