CVE List

Id CVE No. Status Description Phase Votes Comments Actions
21525  CVE-2006-5421  Candidate  WSN Forum 1.3.4 and earlier allows remote attackers to execute arbitrary PHP code via a modified pathname in the pathtoconfig parameter that points to an avatar image that contains PHP code, which is then accessed from prestart.php. NOTE: this issue has been labeled remote file inclusion, but that label only applies to the attack, not the underlying vulnerability.  Assigned (20061019)  None (candidate not yet proposed)    View
87061  CVE-2016-0765  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) action parameter.  Assigned (20151216)  None (candidate not yet proposed)    View
21781  CVE-2006-5677  Candidate  resmom/start_exec.c in pbs_mom in TORQUE Resource Manager 2.0.0p8 and earlier allows local users to create arbitrary files via a symlink attack on (1) a job output file in /usr/spool/PBS/spool and possibly (2) a job file in /usr/spool/PBS/mom_priv/jobs.  Assigned (20061102)  None (candidate not yet proposed)    View
87317  CVE-2016-1000019  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160712)  None (candidate not yet proposed)    View
22037  CVE-2006-5933  Candidate  SQL injection vulnerability in update.asp in UltraSite 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20061115)  None (candidate not yet proposed)    View

Page 1702 of 20943, showing 5 records out of 104715 total, starting on record 8506, ending on 8510

Actions