CVE List

Id CVE No. Status Description Phase Votes Comments Actions
36628  CVE-2008-6511  Candidate  Open redirect vulnerability in login.jsp in Openfire 3.6.0a and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter.  Assigned (20090323)  None (candidate not yet proposed)    View
102164  CVE-2017-5344  Candidate  An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet performs string interpolation and direct SQL query execution. SQL quote escaping and a keyword blacklist were implemented in a new class, SQLUtil (main/java/com/dotmarketing/common/util/SQLUtil.java), as part of the remediation of CVE-2016-8902; however, these can be overcome in the case of the q and inode parameters to the /categoriesServlet path. Overcoming these controls permits a number of blind boolean SQL injection vectors in either parameter. The /categoriesServlet web path can be accessed remotely and without authentication in a default dotCMS deployment.  Assigned (20170111)  None (candidate not yet proposed)    View
36884  CVE-2008-6767  Candidate  wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request.  Assigned (20090428)  None (candidate not yet proposed)    View
102420  CVE-2017-5600  Candidate  The Data Warehouse component in NetApp OnCommand Insight before 7.2.3 allows remote attackers to obtain administrative access by leveraging a default privileged account.  Assigned (20170127)  None (candidate not yet proposed)    View
37140  CVE-2008-7023  Candidate  Aruba Mobility Controller running ArubaOS 3.3.1.16, and possibly other versions, installs the same default X.509 certificate for all installations, which allows remote attackers to bypass authentication. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product"s security documentation.  Assigned (20090821)  None (candidate not yet proposed)    View

Page 1630 of 20943, showing 5 records out of 104715 total, starting on record 8146, ending on 8150

Actions