CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
41698 | CVE-2009-4263 | Candidate | SQL injection vulnerability in main_forum.php in PTCPay GeN3 forum 1.3 allows remote attackers to execute arbitrary SQL commands via the cat parameter. | Assigned (20091210) | None (candidate not yet proposed) | View | |
41954 | CVE-2009-4519 | Candidate | Multiple unspecified vulnerabilities in Ortro before 1.3.4 have unknown impact and attack vectors. | Assigned (20091231) | None (candidate not yet proposed) | View | |
42210 | CVE-2009-4775 | Candidate | Format string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of service (crash) via format string specifiers in the status code portion of an HTTP response. | Assigned (20100421) | None (candidate not yet proposed) | View | |
42466 | CVE-2009-5031 | Candidate | ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks via a single quote in a request parameter in the Content-Disposition field of a request with a multipart/form-data Content-Type header. | Assigned (20101209) | None (candidate not yet proposed) | View | |
42722 | CVE-2010-0138 | Candidate | Buffer overflow in Cisco CiscoWorks Internetwork Performance Monitor (IPM) 2.6 and earlier on Windows, as distributed in CiscoWorks LAN Management Solution (LMS), allows remote attackers to execute arbitrary code via a malformed getProcessName CORBA General Inter-ORB Protocol (GIOP) request, related to a "third-party component," aka Bug ID CSCsv62350. | Assigned (20100104) | None (candidate not yet proposed) | View |
Page 18652 of 20943, showing 5 records out of 104715 total, starting on record 93256, ending on 93260