CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
18406 | CVE-2006-2302 | Candidate | SQL injection vulnerability in admin_default.asp in DUGallery 2.x allows remote attackers to execute arbitrary SQL commands via the (1) Login or (2) password field. | Assigned (20060511) | None (candidate not yet proposed) | View | |
83942 | CVE-2015-6665 | Candidate | Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag. | Assigned (20150824) | None (candidate not yet proposed) | View | |
18662 | CVE-2006-2558 | Candidate | Cross-site scripting (XSS) vulnerability in IpLogger 1.7 and earlier allows remote attackers to inject arbitrary HTML or web script via the User-Agent (useragent) header in an HTTP request, which is not filtered when the log files are viewed. | Assigned (20060523) | None (candidate not yet proposed) | View | |
84198 | CVE-2015-6921 | Candidate | Cross-site scripting (XSS) vulnerability in the Zendesk Feedback Tab module 7.x-1.x before 7.x-1.1 for Drupal allows remote administrators with the "Configure Zendesk Feedback Tab" permission to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20150911) | None (candidate not yet proposed) | View | |
18918 | CVE-2006-2814 | Candidate | Multiple buffer overflows in the (1) vGetPost and (2) main functions in easy-scart.c through easy-scart6.c in iShopCart allow remote attackers to execute arbitrary code by sending a large amount of data containing "Submit" in an sslinvoice action, and allow remote attackers to have an unknown impact via a large amount of posted data. | Assigned (20060605) | None (candidate not yet proposed) | View |
Page 18926 of 20943, showing 5 records out of 104715 total, starting on record 94626, ending on 94630