CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
18150 | CVE-2006-2046 | Candidate | Multiple SQL injection vulnerabilities in Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) keywords parameters in (a) Results.cfm, and the (3) ProdID parameter in (b) Details.cfm. | Assigned (20060426) | None (candidate not yet proposed) | View | |
83686 | CVE-2015-6409 | Candidate | Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks and trigger cleartext XMPP sessions via unspecified vectors, aka Bug ID CSCuw87419. | Assigned (20150817) | None (candidate not yet proposed) | View | |
18406 | CVE-2006-2302 | Candidate | SQL injection vulnerability in admin_default.asp in DUGallery 2.x allows remote attackers to execute arbitrary SQL commands via the (1) Login or (2) password field. | Assigned (20060511) | None (candidate not yet proposed) | View | |
83942 | CVE-2015-6665 | Candidate | Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag. | Assigned (20150824) | None (candidate not yet proposed) | View | |
18662 | CVE-2006-2558 | Candidate | Cross-site scripting (XSS) vulnerability in IpLogger 1.7 and earlier allows remote attackers to inject arbitrary HTML or web script via the User-Agent (useragent) header in an HTTP request, which is not filtered when the log files are viewed. | Assigned (20060523) | None (candidate not yet proposed) | View |
Page 18901 of 20943, showing 5 records out of 104715 total, starting on record 94501, ending on 94505