CVE List

Id CVE No. Status Description Phase Votes Comments Actions
39659  CVE-2009-2224  Candidate  Directory traversal vulnerability in ang/shared/flags.php in AN Guestbook 0.7.8, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the g_lang parameter.  Assigned (20090626)  None (candidate not yet proposed)    View
39915  CVE-2009-2480  Candidate  Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type 4.24, and 4.25 when global templates are not initialized, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20090716)  None (candidate not yet proposed)    View
40171  CVE-2009-2736  Candidate  Static code injection vulnerability in admin.php in sun-jester OpenNews 1.0 allows remote authenticated administrators to inject arbitrary PHP code into config.php via the "Overall Width" field in a setconfig action.  Assigned (20090810)  None (candidate not yet proposed)    View
40427  CVE-2009-2992  Candidate  An unspecified ActiveX control in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 does not properly validate input, which allows attackers to cause a denial of service via unknown vectors.  Assigned (20090827)  None (candidate not yet proposed)    View
40683  CVE-2009-3248  Candidate  Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack the authentication of Admin users for requests that modify the news feed system via the rssurl parameter in a Save action to index.php.  Assigned (20090918)  None (candidate not yet proposed)    View

Page 18722 of 20943, showing 5 records out of 104715 total, starting on record 93606, ending on 93610

Actions