CVE List

Id CVE No. Status Description Phase Votes Comments Actions
18405  CVE-2006-2301  Candidate  SQL injection vulnerability in admin_default.asp in OzzyWork Galeri allows remote attackers to execute arbitrary SQL commands via the (1) Login or (2) password fields.  Assigned (20060511)  None (candidate not yet proposed)    View
83941  CVE-2015-6664  Candidate  XML external entity (XXE) vulnerability in the application import functionality in SAP Mobile Platform 2.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via crafted XML data, aka SAP Security Note 2152227.  Assigned (20150824)  None (candidate not yet proposed)    View
18661  CVE-2006-2557  Candidate  PHP remote file inclusion vulnerability in extras/poll/poll.php in Florian Amrhein NewsPortal before 0.37, and TR Newsportal (TRanx rebuilded), allows remote attackers to execute arbitrary PHP code via a URL in the file_newsportal parameter.  Assigned (20060523)  None (candidate not yet proposed)    View
84197  CVE-2015-6920  Candidate  Cross-site scripting (XSS) vulnerability in js/window.php in the sourceAFRICA plugin 0.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wpbase parameter.  Assigned (20150911)  None (candidate not yet proposed)    View
18917  CVE-2006-2813  Candidate  Directory traversal vulnerability in easy-scart.cgi in iShopCart allows remote attackers to read arbitrary files via a .. (dot dot) in the query string.  Assigned (20060605)  None (candidate not yet proposed)    View

Page 18822 of 20943, showing 5 records out of 104715 total, starting on record 94106, ending on 94110

Actions