CVE List

Id CVE No. Status Description Phase Votes Comments Actions
19954  CVE-2006-3850  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in upgrader.php in Vanilla CMS 1.0.1 and earlier, when /conf/old_settings.php exists, allows remote attackers to execute arbitrary PHP code via a URL in the RootDirectory parameter. NOTE: this issue has been disputed by a third party who states that the RootDirectory parameter is initialized before being used, for version 1.0. CVE analysis concurs with the dispute, but it is unclear whether older versions are affected.  Assigned (20060725)  None (candidate not yet proposed)    View
85490  CVE-2015-8213  Candidate  The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1.9rc2 might allow remote attackers to obtain sensitive application secrets via a settings key in place of a date/time format setting, as demonstrated by SECRET_KEY.  Assigned (20151114)  None (candidate not yet proposed)    View
20210  CVE-2006-4106  Candidate  Cross-site scripting (XSS) vulnerability in blursoft blur6ex 0.3 allows remote attackers to inject arbitrary web script or HTML via a comment title.  Assigned (20060814)  None (candidate not yet proposed)    View
85746  CVE-2015-8469  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20151204)  None (candidate not yet proposed)    View
20466  CVE-2006-4362  Candidate  Cross-site scripting (XSS) vulnerability in getad.php in Diesel Paid Mail allows remote attackers to inject arbitrary web script or HTML via the ps parameter.  Assigned (20060825)  None (candidate not yet proposed)    View

Page 18731 of 20943, showing 5 records out of 104715 total, starting on record 93651, ending on 93655

Actions