CVE List

Id CVE No. Status Description Phase Votes Comments Actions
36630  CVE-2008-6513  Candidate  Unrestricted file upload vulnerability in saa.php in Andy"s PHP Knowledgebase (aphpkb) 0.92.9 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a link that is listed by authors.php.  Assigned (20090324)  None (candidate not yet proposed)    View
102166  CVE-2017-5346  Candidate  SQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter to gxadmin/index.php.  Assigned (20170111)  None (candidate not yet proposed)    View
36886  CVE-2008-6769  Candidate  Unrestricted file upload vulnerability in upload.php in YourPlace 1.0.2 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file.  Assigned (20090429)  None (candidate not yet proposed)    View
102422  CVE-2017-5602  Candidate  An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application"s display. This allows for various kinds of social engineering attacks. This CVE is for jappix 1.0.0 to 1.1.6.  Assigned (20170128)  None (candidate not yet proposed)    View
37142  CVE-2008-7025  Candidate  TrueVector in Check Point ZoneAlarm 8.0.020.000, with vsmon.exe running, allows remote HTTP proxies to cause a denial of service (crash) and disable the HIDS module via a crafted response.  Assigned (20090821)  None (candidate not yet proposed)    View

Page 1784 of 20943, showing 5 records out of 104715 total, starting on record 8916, ending on 8920

Actions