CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5096 | CVE-2002-0706 | Candidate | UserManager.js in the Web Reports Server for SurfControl SuperScout WebFilter uses weak encryption for administrator functions, which allows remote attackers to decrypt the administrative password using a hard-coded key in a Javascript function. | Modified (20050610) | ACCEPT(1) Baker | NOOP(4) Cole, Cox, Green, Wall | View | |
70632 | CVE-2014-3336 | Candidate | SQL injection vulnerability in the web framework in Cisco Unity Connection 9.1(2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted request, aka Bug ID CSCuq31016. | Assigned (20140507) | None (candidate not yet proposed) | View | |
70888 | CVE-2014-3592 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20140514) | None (candidate not yet proposed) | View | |
71144 | CVE-2014-3848 | Candidate | The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to obtain database credentials via the i4w_dbinfo parameter. | Assigned (20140523) | None (candidate not yet proposed) | View | |
5864 | CVE-2002-1480 | Candidate | Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script into guestbook pages, which is executed when the administrator deletes the entry. | Proposed (20030317) | ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall | View |
Page 19040 of 20943, showing 5 records out of 104715 total, starting on record 95196, ending on 95200