CVE List

Id CVE No. Status Description Phase Votes Comments Actions
47108  CVE-2010-4524  Candidate  Cross-site scripting (XSS) vulnerability in lib/mhtxthtml.pl in MHonArc 2.6.16 allows remote attackers to inject arbitrary web script or HTML via a malformed start tag and end tag for a SCRIPT element, as demonstrated by <scr<body>ipt> and </scr<body>ipt> sequences.  Assigned (20101209)  None (candidate not yet proposed)    View
47364  CVE-2010-4780  Candidate  SQL injection vulnerability in the check_banlist function in includes/sessions.php in Enano CMS 1.1.7pl1; 1.0.6pl2; and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2 allows remote attackers to execute arbitrary SQL commands via the email parameter to index.php. NOTE: some of these details are obtained from third party information.  Assigned (20110407)  None (candidate not yet proposed)    View
47620  CVE-2010-5036  Candidate  SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter.  Assigned (20111102)  None (candidate not yet proposed)    View
47876  CVE-2010-5292  Candidate  Amberdms Billing System (ABS) before 1.4.1, when a multi-instance installation is configured, might allow local users to obtain sensitive information by reading the cache in between runs of the include/cron/services_usage.php cron job.  Assigned (20140110)  None (candidate not yet proposed)    View
48132  CVE-2011-0220  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20101223)  None (candidate not yet proposed)    View

Page 1533 of 20943, showing 5 records out of 104715 total, starting on record 7661, ending on 7665

Actions