CVE List

Id CVE No. Status Description Phase Votes Comments Actions
19426  CVE-2006-3322  Candidate  SQL injection vulnerability in includes/functions_logging.php in phpRaid 3.0.5, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the log_hack function.  Assigned (20060630)  None (candidate not yet proposed)    View
84962  CVE-2015-7685  Candidate  GLPI before 0.85.3 allows remote authenticated users to create super-admin accounts by leveraging permissions to create a user and the _profiles_id parameter to front/user.form.php.  Assigned (20151002)  None (candidate not yet proposed)    View
19682  CVE-2006-3578  Candidate  Directory traversal vulnerability in Fujitsu ServerView 2.50 up to 3.60L98 and 4.10L11 up to 4.11L81 allows remote attackers to read arbitrary files via unspecified vectors.  Assigned (20060712)  None (candidate not yet proposed)    View
85218  CVE-2015-7941  Candidate  libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections function in parser.c, as demonstrated by non-terminated entities.  Assigned (20151022)  None (candidate not yet proposed)    View
19938  CVE-2006-3834  Candidate  EJ3 TOPo 2.2.178 includes the password in cleartext in the ID field to index.php, which allows context-dependent attackers to obtain entry passwords via log files, referrers, or other vectors.  Assigned (20060724)  None (candidate not yet proposed)    View

Page 18619 of 20943, showing 5 records out of 104715 total, starting on record 93091, ending on 93095

Actions