CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
21525 | CVE-2006-5421 | Candidate | WSN Forum 1.3.4 and earlier allows remote attackers to execute arbitrary PHP code via a modified pathname in the pathtoconfig parameter that points to an avatar image that contains PHP code, which is then accessed from prestart.php. NOTE: this issue has been labeled remote file inclusion, but that label only applies to the attack, not the underlying vulnerability. | Assigned (20061019) | None (candidate not yet proposed) | View | |
87061 | CVE-2016-0765 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) action parameter. | Assigned (20151216) | None (candidate not yet proposed) | View | |
21781 | CVE-2006-5677 | Candidate | resmom/start_exec.c in pbs_mom in TORQUE Resource Manager 2.0.0p8 and earlier allows local users to create arbitrary files via a symlink attack on (1) a job output file in /usr/spool/PBS/spool and possibly (2) a job file in /usr/spool/PBS/mom_priv/jobs. | Assigned (20061102) | None (candidate not yet proposed) | View | |
87317 | CVE-2016-1000019 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20160712) | None (candidate not yet proposed) | View | |
22037 | CVE-2006-5933 | Candidate | SQL injection vulnerability in update.asp in UltraSite 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Assigned (20061115) | None (candidate not yet proposed) | View |
Page 1702 of 20943, showing 5 records out of 104715 total, starting on record 8506, ending on 8510