CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
36630 | CVE-2008-6513 | Candidate | Unrestricted file upload vulnerability in saa.php in Andy"s PHP Knowledgebase (aphpkb) 0.92.9 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a link that is listed by authors.php. | Assigned (20090324) | None (candidate not yet proposed) | View | |
102166 | CVE-2017-5346 | Candidate | SQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter to gxadmin/index.php. | Assigned (20170111) | None (candidate not yet proposed) | View | |
36886 | CVE-2008-6769 | Candidate | Unrestricted file upload vulnerability in upload.php in YourPlace 1.0.2 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file. | Assigned (20090429) | None (candidate not yet proposed) | View | |
102422 | CVE-2017-5602 | Candidate | An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application"s display. This allows for various kinds of social engineering attacks. This CVE is for jappix 1.0.0 to 1.1.6. | Assigned (20170128) | None (candidate not yet proposed) | View | |
37142 | CVE-2008-7025 | Candidate | TrueVector in Check Point ZoneAlarm 8.0.020.000, with vsmon.exe running, allows remote HTTP proxies to cause a denial of service (crash) and disable the HIDS module via a crafted response. | Assigned (20090821) | None (candidate not yet proposed) | View |
Page 1784 of 20943, showing 5 records out of 104715 total, starting on record 8916, ending on 8920