CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
17395 | CVE-2006-1291 | Candidate | publish.ical.php in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier does not require authentication for write access to the calendars directory, which allows remote attackers to upload and execute arbitrary PHP scripts via a WebDAV PUT request with a filename containing a .php extension and a trailing null character. | Assigned (20060319) | None (candidate not yet proposed) | View | |
82931 | CVE-2015-5654 | Candidate | Cross-site scripting (XSS) vulnerability in Dojo Toolkit before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20150724) | None (candidate not yet proposed) | View | |
17651 | CVE-2006-1547 | Candidate | ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils. | Assigned (20060330) | None (candidate not yet proposed) | View | |
83187 | CVE-2015-5910 | Candidate | IDE Xcode Server in Apple Xcode before 7.0 does not ensure that server traffic is encrypted, which allows remote attackers to obtain sensitive information by sniffing the network. | Assigned (20150806) | None (candidate not yet proposed) | View | |
17907 | CVE-2006-1803 | Candidate | Cross-site scripting (XSS) vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to inject arbitrary web script or HTML via the sql_query parameter. | Assigned (20060417) | None (candidate not yet proposed) | View |
Page 18804 of 20943, showing 5 records out of 104715 total, starting on record 94016, ending on 94020