CVE List

Id CVE No. Status Description Phase Votes Comments Actions
24811  CVE-2007-1454  Candidate  ext/filter in PHP 5.2.0, when FILTER_SANITIZE_STRING is used with the FILTER_FLAG_STRIP_LOW flag, does not properly strip HTML tags, which allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML with a "<" character followed by certain whitespace characters, which passes one filter but is collapsed into a valid tag, as demonstrated using %0b.  Assigned (20070314)  None (candidate not yet proposed)    View
90347  CVE-2016-3528  Candidate  Unspecified vulnerability in the Oracle Internet Expenses component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect availability via vectors related to Expenses Admin Utilities.  Assigned (20160317)  None (candidate not yet proposed)    View
25067  CVE-2007-1710  Candidate  The readfile function in PHP 4.4.4, 5.1.6, and 5.2.1 allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files by referring to local files with a certain URL syntax instead of a pathname syntax, as demonstrated by a filename preceded a "php://../../" sequence.  Assigned (20070326)  None (candidate not yet proposed)    View
90603  CVE-2016-3784  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160330)  None (candidate not yet proposed)    View
25323  CVE-2007-1966  Candidate  Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookie.  Assigned (20070410)  None (candidate not yet proposed)    View

Page 18699 of 20943, showing 5 records out of 104715 total, starting on record 93491, ending on 93495

Actions