CVE List

Id CVE No. Status Description Phase Votes Comments Actions
41495  CVE-2009-4060  Candidate  SQL injection vulnerability in includes/content/viewProd.inc.php in CubeCart before 4.3.7 remote attackers to execute arbitrary SQL commands via the productId parameter.  Assigned (20091123)  None (candidate not yet proposed)    View
41751  CVE-2009-4316  Candidate  Cross-site scripting (XSS) vulnerability in searchresults_main.php in ZeeLyrics 3x allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20091214)  None (candidate not yet proposed)    View
42007  CVE-2009-4572  Candidate  Cross-site request forgery (CSRF) vulnerability in PhpShop 0.8.1 allows remote attackers to hijack the authentication of arbitrary users for requests that invoke the cartAdd function in a shop/cart action to the default URI.  Assigned (20100105)  None (candidate not yet proposed)    View
42263  CVE-2009-4828  Candidate  Cross-site request forgery (CSRF) vulnerability in administration/admins.php in Ad Manager Pro (aka AdManagerPro) 3.0 allows remote attackers to hijack the authentication of administrators for requests that create new administrative users via an admin_created action. NOTE: some of these details are obtained from third party information.  Assigned (20100427)  None (candidate not yet proposed)    View
42519  CVE-2009-5084  Candidate  IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when com.tivoli.am.fim.infocard.delegates.InfoCardSTSDelegate tracing is enabled, creates a cleartext log entry containing a password, which might allow local users to obtain sensitive information by reading the log data.  Assigned (20110812)  None (candidate not yet proposed)    View

Page 1914 of 20943, showing 5 records out of 104715 total, starting on record 9566, ending on 9570

Actions