CVE List

Id CVE No. Status Description Phase Votes Comments Actions
51987  CVE-2011-4075  Candidate  The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby parameter (aka sortby variable) in a query_engine action to cmd.php, as exploited in the wild in October 2011.  Assigned (20111018)  None (candidate not yet proposed)    View
52243  CVE-2011-4331  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-4110. Reason: This candidate is a duplicate of CVE-2011-4110. Notes: All CVE users should reference CVE-2011-4110 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20111104)  None (candidate not yet proposed)    View
52499  CVE-2011-4587  Candidate  lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.  Assigned (20111129)  None (candidate not yet proposed)    View
52755  CVE-2011-4843  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20111215)  None (candidate not yet proposed)    View
53011  CVE-2011-5099  Candidate  SQL injection vulnerability in helper/popup.php in the ccNewsletter (mod_ccnewsletter) component 1.0.7 through 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20120814)  None (candidate not yet proposed)    View

Page 1602 of 20943, showing 5 records out of 104715 total, starting on record 8006, ending on 8010

Actions