CVE List

Id CVE No. Status Description Phase Votes Comments Actions
20706  CVE-2006-4602  Candidate  Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a filepath parameter that contains a filename with a .php extension, which is uploaded to the img/wiki/ directory.  Assigned (20060906)  None (candidate not yet proposed)    View
86242  CVE-2015-8965  Candidate  Rogue Wave JViews before 8.8 patch 21 and 8.9 before patch 1 allows remote attackers to execute arbitrary Java code that exists in the classpath, such as test code or administration code. The issue exists because the ilog.views.faces.IlvFacesController servlet in jviews-framework-all.jar does not require explicit configuration of servlets that can be called.  Assigned (20161008)  None (candidate not yet proposed)    View
20962  CVE-2006-4858  Candidate  PHP remote file inclusion vulnerability in install.serverstat.php in the Serverstat (com_serverstat) 0.4.4 and earlier component for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.  Assigned (20060919)  None (candidate not yet proposed)    View
86498  CVE-2016-0202  Candidate  A vulnerability has been identified in tasks, backend object generated for handling any action performed by the application in IBM Cloud Orchestrator. It is possible for an authenticated user to view any task of the current users domain.  Assigned (20151208)  None (candidate not yet proposed)    View
21218  CVE-2006-5114  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in wgate in SAP Internet Transaction Server (ITS) 6.1 and 6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) ~urlmime or (2) ~command parameter, different vectors than CVE-2003-0749.  Assigned (20061002)  None (candidate not yet proposed)    View

Page 18621 of 20943, showing 5 records out of 104715 total, starting on record 93101, ending on 93105

Actions