CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9958  CVE-2004-1530  Candidate  SQL injection vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the (1) eid or (2) cid parameters.  Assigned (20050218)  None (candidate not yet proposed)    View
75494  CVE-2014-8193  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20141010)  None (candidate not yet proposed)    View
10214  CVE-2004-1786  Candidate  PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive information via a direct request to 8275.mdb.  Assigned (20050504)  None (candidate not yet proposed)    View
75750  CVE-2014-8449  Candidate  Integer overflow in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors.  Assigned (20141022)  None (candidate not yet proposed)    View
10470  CVE-2004-2044  Candidate  PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERVER["PHP_SELF"] to identify the calling script, which allows remote attackers to directly access scripts, obtain path information via a PHP error message, and possibly gain access, as demonstrated using an HTTP request that contains the "admin.php" string.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 18873 of 20943, showing 5 records out of 104715 total, starting on record 94361, ending on 94365

Actions