CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
22037 | CVE-2006-5933 | Candidate | SQL injection vulnerability in update.asp in UltraSite 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Assigned (20061115) | None (candidate not yet proposed) | View | |
87573 | CVE-2016-10075 | Candidate | The tqdm._version module in tqdm versions 4.4.1 and 4.10 allows local users to execute arbitrary code via a crafted repo with a malicious git log in the current working directory. | Assigned (20161228) | None (candidate not yet proposed) | View | |
22293 | CVE-2006-6189 | Candidate | SQL injection vulnerability in displayCalendar.asp in ClickTech Click Blog allows remote attackers to execute arbitrary SQL commands via the date parameter. | Assigned (20061130) | None (candidate not yet proposed) | View | |
87829 | CVE-2016-10308 | Candidate | Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device"s web interface and grants access to the underlying embedded Linux OS on the device, allowing full control over it. | Assigned (20170329) | None (candidate not yet proposed) | View | |
22549 | CVE-2006-6445 | Candidate | Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php. | Assigned (20061210) | None (candidate not yet proposed) | View |
Page 1725 of 20943, showing 5 records out of 104715 total, starting on record 8621, ending on 8625