CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
39659 | CVE-2009-2224 | Candidate | Directory traversal vulnerability in ang/shared/flags.php in AN Guestbook 0.7.8, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the g_lang parameter. | Assigned (20090626) | None (candidate not yet proposed) | View | |
39915 | CVE-2009-2480 | Candidate | Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type 4.24, and 4.25 when global templates are not initialized, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20090716) | None (candidate not yet proposed) | View | |
40171 | CVE-2009-2736 | Candidate | Static code injection vulnerability in admin.php in sun-jester OpenNews 1.0 allows remote authenticated administrators to inject arbitrary PHP code into config.php via the "Overall Width" field in a setconfig action. | Assigned (20090810) | None (candidate not yet proposed) | View | |
40427 | CVE-2009-2992 | Candidate | An unspecified ActiveX control in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 does not properly validate input, which allows attackers to cause a denial of service via unknown vectors. | Assigned (20090827) | None (candidate not yet proposed) | View | |
40683 | CVE-2009-3248 | Candidate | Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack the authentication of Admin users for requests that modify the news feed system via the rssurl parameter in a Save action to index.php. | Assigned (20090918) | None (candidate not yet proposed) | View |
Page 18722 of 20943, showing 5 records out of 104715 total, starting on record 93606, ending on 93610