CVE List

Id CVE No. Status Description Phase Votes Comments Actions
39187  CVE-2009-1752  Candidate  exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which allows remote attackers to gain privileges a direct request. NOTE: some of these details are obtained from third party information.  Assigned (20090521)  None (candidate not yet proposed)    View
39443  CVE-2009-2008  Candidate  Multiple SQL injection vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) uInfo parameter to main/tracking/userLog.php and the (2) course parameter to main/mySpace/lp_tracking.php, a different vector than CVE-2009-2006.2.  Assigned (20090608)  None (candidate not yet proposed)    View
39699  CVE-2009-2264  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20090629)  None (candidate not yet proposed)    View
39955  CVE-2009-2520  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20090717)  None (candidate not yet proposed)    View
40211  CVE-2009-2776  Candidate  SQL injection vulnerability in showresult.asp in Smart ASP Survey allows remote attackers to execute arbitrary SQL commands via the catid parameter.  Assigned (20090814)  None (candidate not yet proposed)    View

Page 1592 of 20943, showing 5 records out of 104715 total, starting on record 7956, ending on 7960

Actions