CVE List

Id CVE No. Status Description Phase Votes Comments Actions
18956  CVE-2006-2852  Candidate  PHP remote file inclusion vulnerability in dotWidget CMS 1.0.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the file_path parameter in (1) index.php, (2) feedback.php, and (3) printfriendly.php.  Assigned (20060605)  None (candidate not yet proposed)    View
84492  CVE-2015-7215  Candidate  The importScripts function in the Web Workers API implementation in Mozilla Firefox before 43.0 allows remote attackers to bypass the Same Origin Policy by triggering use of the no-cors mode in the fetch API to attempt resource access that throws an exception, leading to information disclosure after a rethrow.  Assigned (20150916)  None (candidate not yet proposed)    View
19212  CVE-2006-3108  Candidate  Cross-site scripting (XSS) vulnerability in EmailArchitect Email Server 6.1 allows remote attackers to inject arbitrary Javascript via an HTML div tag with a carriage return between the onmouseover attribute and its value, which bypasses the mail filter.  Assigned (20060620)  None (candidate not yet proposed)    View
84748  CVE-2015-7471  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150929)  None (candidate not yet proposed)    View
19468  CVE-2006-3364  Candidate  SQL injection vulnerability in index.php in the NP_SEO plugin in BLOG:CMS before 4.1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20060706)  None (candidate not yet proposed)    View

Page 1595 of 20943, showing 5 records out of 104715 total, starting on record 7971, ending on 7975

Actions