CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40983  CVE-2009-3548  Candidate  The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.  Assigned (20091005)  None (candidate not yet proposed)    View
41239  CVE-2009-3804  Candidate  Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via (1) the pid parameter, which is not properly handled by the store function in modules/forum/class/class.forumposts.php, or (2) the topic_id parameter.  Assigned (20091027)  None (candidate not yet proposed)    View
41495  CVE-2009-4060  Candidate  SQL injection vulnerability in includes/content/viewProd.inc.php in CubeCart before 4.3.7 remote attackers to execute arbitrary SQL commands via the productId parameter.  Assigned (20091123)  None (candidate not yet proposed)    View
41751  CVE-2009-4316  Candidate  Cross-site scripting (XSS) vulnerability in searchresults_main.php in ZeeLyrics 3x allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20091214)  None (candidate not yet proposed)    View
42007  CVE-2009-4572  Candidate  Cross-site request forgery (CSRF) vulnerability in PhpShop 0.8.1 allows remote attackers to hijack the authentication of arbitrary users for requests that invoke the cartAdd function in a shop/cart action to the default URI.  Assigned (20100105)  None (candidate not yet proposed)    View

Page 1890 of 20943, showing 5 records out of 104715 total, starting on record 9446, ending on 9450

Actions