CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
56819 | CVE-2012-3576 | Candidate | Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/wpstorecart. | Assigned (20120615) | None (candidate not yet proposed) | View | |
57075 | CVE-2012-3832 | Candidate | Cross-site scripting (XSS) vulnerability in decoda/Decoda.php in Decoda before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to (1) b or (2) div tags. | Assigned (20120703) | None (candidate not yet proposed) | View | |
57331 | CVE-2012-4088 | Candidate | The FTP server in Cisco Unified Computing System (UCS) has a hardcoded password for an unspecified user account, which makes it easier for remote attackers to read or modify files by leveraging knowledge of this password, aka Bug ID CSCtg20769. | Assigned (20120731) | None (candidate not yet proposed) | View | |
57587 | CVE-2012-4344 | Candidate | Cross-site scripting (XSS) vulnerability in Ipswitch WhatsUp Gold 15.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the SNMP system name of the attacking host. | Assigned (20120815) | None (candidate not yet proposed) | View | |
57843 | CVE-2012-4600 | Candidate | Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.14, 3.0.x before 3.0.16, and 3.1.x before 3.1.10, when Firefox or Opera is used, allows remote attackers to inject arbitrary web script or HTML via an e-mail message body with nested HTML tags. | Assigned (20120822) | None (candidate not yet proposed) | View |
Page 18852 of 20943, showing 5 records out of 104715 total, starting on record 94256, ending on 94260