CVE List

Id CVE No. Status Description Phase Votes Comments Actions
51698  CVE-2011-3786  Candidate  PHProjekt 6.0.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by Setup/Controllers/IndexController.php.  Assigned (20110923)  None (candidate not yet proposed)    View
51954  CVE-2011-4042  Candidate  An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code by using a crafted HTML document to obtain control of a function pointer.  Assigned (20111013)  None (candidate not yet proposed)    View
52210  CVE-2011-4298  Candidate  Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote attackers to hijack the authentication of arbitrary users for requests that modify wiki data.  Assigned (20111104)  None (candidate not yet proposed)    View
52466  CVE-2011-4554  Candidate  One Click Orgs before 1.2.3 allows remote authenticated users to trigger crafted SMTP traffic via (1) " (double quote) and newline characters in an org name or (2) " (double quote) characters in an e-mail address, related to a "2nd Order SMTP Injection" issue.  Assigned (20111127)  None (candidate not yet proposed)    View
52722  CVE-2011-4810  Candidate  Multiple directory traversal vulnerabilities in WHMCompleteSolution (WHMCS) 3.x and 4.x allow remote attackers to read arbitrary files via the templatefile parameter to (1) submitticket.php and (2) downloads.php, and (3) the report parameter to admin/reports.php.  Assigned (20111213)  None (candidate not yet proposed)    View

Page 18771 of 20943, showing 5 records out of 104715 total, starting on record 93851, ending on 93855

Actions