CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
40215 | CVE-2009-2780 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in 68 Classifieds 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to category.php, view parameter to (2) login.php and (3) viewlisting.php, page parameter to (4) searchresults.php and (5) toplistings.php, and (6) member parameter to viewmember.php. | Assigned (20090817) | None (candidate not yet proposed) | View | |
40471 | CVE-2009-3036 | Candidate | Cross-site scripting (XSS) vulnerability in the console in Symantec IM Manager 8.3 and 8.4 before 8.4.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20090831) | None (candidate not yet proposed) | View | |
40727 | CVE-2009-3292 | Candidate | Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing." | Assigned (20090922) | None (candidate not yet proposed) | View | |
40983 | CVE-2009-3548 | Candidate | The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges. | Assigned (20091005) | None (candidate not yet proposed) | View | |
41239 | CVE-2009-3804 | Candidate | Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via (1) the pid parameter, which is not properly handled by the store function in modules/forum/class/class.forumposts.php, or (2) the topic_id parameter. | Assigned (20091027) | None (candidate not yet proposed) | View |
Page 1913 of 20943, showing 5 records out of 104715 total, starting on record 9561, ending on 9565