CVE List

Id CVE No. Status Description Phase Votes Comments Actions
18406  CVE-2006-2302  Candidate  SQL injection vulnerability in admin_default.asp in DUGallery 2.x allows remote attackers to execute arbitrary SQL commands via the (1) Login or (2) password field.  Assigned (20060511)  None (candidate not yet proposed)    View
83942  CVE-2015-6665  Candidate  Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag.  Assigned (20150824)  None (candidate not yet proposed)    View
18662  CVE-2006-2558  Candidate  Cross-site scripting (XSS) vulnerability in IpLogger 1.7 and earlier allows remote attackers to inject arbitrary HTML or web script via the User-Agent (useragent) header in an HTTP request, which is not filtered when the log files are viewed.  Assigned (20060523)  None (candidate not yet proposed)    View
84198  CVE-2015-6921  Candidate  Cross-site scripting (XSS) vulnerability in the Zendesk Feedback Tab module 7.x-1.x before 7.x-1.1 for Drupal allows remote administrators with the "Configure Zendesk Feedback Tab" permission to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20150911)  None (candidate not yet proposed)    View
18918  CVE-2006-2814  Candidate  Multiple buffer overflows in the (1) vGetPost and (2) main functions in easy-scart.c through easy-scart6.c in iShopCart allow remote attackers to execute arbitrary code by sending a large amount of data containing "Submit" in an sslinvoice action, and allow remote attackers to have an unknown impact via a large amount of posted data.  Assigned (20060605)  None (candidate not yet proposed)    View

Page 18926 of 20943, showing 5 records out of 104715 total, starting on record 94626, ending on 94630

Actions