CVE List

Id CVE No. Status Description Phase Votes Comments Actions
36070  CVE-2008-5953  Candidate  Directory traversal vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter to the default URI.  Assigned (20090123)  None (candidate not yet proposed)    View
101606  CVE-2017-4786  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161226)  None (candidate not yet proposed)    View
36326  CVE-2008-6209  Candidate  SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.  Assigned (20090219)  None (candidate not yet proposed)    View
101862  CVE-2017-5042  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170102)  None (candidate not yet proposed)    View
36582  CVE-2008-6465  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in login.php in webshell4 in Parallels H-Sphere 3.0.0 P9 and 3.1 P1 allow remote attackers to inject arbitrary web script or HTML via the (1) err, (2) errorcode, and (3) login parameters.  Assigned (20090313)  None (candidate not yet proposed)    View

Page 18929 of 20943, showing 5 records out of 104715 total, starting on record 94641, ending on 94645

Actions