CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
51698 | CVE-2011-3786 | Candidate | PHProjekt 6.0.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by Setup/Controllers/IndexController.php. | Assigned (20110923) | None (candidate not yet proposed) | View | |
51954 | CVE-2011-4042 | Candidate | An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code by using a crafted HTML document to obtain control of a function pointer. | Assigned (20111013) | None (candidate not yet proposed) | View | |
52210 | CVE-2011-4298 | Candidate | Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote attackers to hijack the authentication of arbitrary users for requests that modify wiki data. | Assigned (20111104) | None (candidate not yet proposed) | View | |
52466 | CVE-2011-4554 | Candidate | One Click Orgs before 1.2.3 allows remote authenticated users to trigger crafted SMTP traffic via (1) " (double quote) and newline characters in an org name or (2) " (double quote) characters in an e-mail address, related to a "2nd Order SMTP Injection" issue. | Assigned (20111127) | None (candidate not yet proposed) | View | |
52722 | CVE-2011-4810 | Candidate | Multiple directory traversal vulnerabilities in WHMCompleteSolution (WHMCS) 3.x and 4.x allow remote attackers to read arbitrary files via the templatefile parameter to (1) submitticket.php and (2) downloads.php, and (3) the report parameter to admin/reports.php. | Assigned (20111213) | None (candidate not yet proposed) | View |
Page 18771 of 20943, showing 5 records out of 104715 total, starting on record 93851, ending on 93855