CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
18956 | CVE-2006-2852 | Candidate | PHP remote file inclusion vulnerability in dotWidget CMS 1.0.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the file_path parameter in (1) index.php, (2) feedback.php, and (3) printfriendly.php. | Assigned (20060605) | None (candidate not yet proposed) | View | |
84492 | CVE-2015-7215 | Candidate | The importScripts function in the Web Workers API implementation in Mozilla Firefox before 43.0 allows remote attackers to bypass the Same Origin Policy by triggering use of the no-cors mode in the fetch API to attempt resource access that throws an exception, leading to information disclosure after a rethrow. | Assigned (20150916) | None (candidate not yet proposed) | View | |
19212 | CVE-2006-3108 | Candidate | Cross-site scripting (XSS) vulnerability in EmailArchitect Email Server 6.1 allows remote attackers to inject arbitrary Javascript via an HTML div tag with a carriage return between the onmouseover attribute and its value, which bypasses the mail filter. | Assigned (20060620) | None (candidate not yet proposed) | View | |
84748 | CVE-2015-7471 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20150929) | None (candidate not yet proposed) | View | |
19468 | CVE-2006-3364 | Candidate | SQL injection vulnerability in index.php in the NP_SEO plugin in BLOG:CMS before 4.1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Assigned (20060706) | None (candidate not yet proposed) | View |
Page 1595 of 20943, showing 5 records out of 104715 total, starting on record 7971, ending on 7975