CVE List

Id CVE No. Status Description Phase Votes Comments Actions
19988  CVE-2006-3884  Candidate  Multiple SQL injection vulnerabilities in links.php in Gonafish LinksCaffe 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) offset and (2) limit parameters, (3) newdays parameter in a new action, and the (4) link_id parameter in a deadlink action. NOTE: this issue can also be used for path disclosure by a forced SQL error, or to modify PHP files using OUTFILE.  Assigned (20060726)  None (candidate not yet proposed)    View
85524  CVE-2015-8247  Candidate  Cross-site scripting (XSS) vulnerability in synnefoclient in Synnefo Internet Management Software (IMS) 2015 allows remote attackers to inject arbitrary web script or HTML via the plan_name parameter to packagehistory/listusagesdata.  Assigned (20151119)  None (candidate not yet proposed)    View
20244  CVE-2006-4140  Candidate  Directory traversal vulnerability in IPCheck Server Monitor before 5.3.3.639/640 allows remote attackers to read arbitrary files via modified .. (dot dot) sequences in the URL, including (1) "..%2f" (encoded "/" slash), "..../" (multiple dot), and "..%255c../" (double-encoded "" backslash).  Assigned (20060814)  None (candidate not yet proposed)    View
85780  CVE-2015-8503  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20151208)  None (candidate not yet proposed)    View
20500  CVE-2006-4396  Candidate  The Apple Type Services (ATS) server in Mac OS X 10.4.8 and earlier does not securely create log files, which allows local users to create and modify arbitrary files via unspecified vectors, possibly relating to a symlink attack.  Assigned (20060828)  None (candidate not yet proposed)    View

Page 1604 of 20943, showing 5 records out of 104715 total, starting on record 8016, ending on 8020

Actions