CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
26089 | CVE-2007-2732 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML via the (1) path parameter to view/search/; or the (2) companyname, (3) country, (4) email, (5) firstname, (6) middlename, (7) required, (8) surname, or (9) title parameter to view/supplynews/. | Assigned (20070516) | None (candidate not yet proposed) | View | |
91625 | CVE-2016-4806 | Candidate | Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access web server sensitive files. | Assigned (20160515) | None (candidate not yet proposed) | View | |
26345 | CVE-2007-2988 | Candidate | A certain admin script in Inout Meta Search Engine sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject arbitrary PHP code, as demonstrated by a request to admin/create_engine.php followed by a request to admin/generate_tabs.php. | Assigned (20070531) | None (candidate not yet proposed) | View | |
91881 | CVE-2016-5062 | Candidate | The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, which allows remote attackers to execute arbitrary Java code by registering MBeans. | Assigned (20160526) | None (candidate not yet proposed) | View | |
26601 | CVE-2007-3244 | Candidate | SQL injection vulnerability in bb-includes/formatting-functions.php in bbPress before 0.8.1 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors to forums/bb-edit.php, as demonstrated by a PRE element, aka the "quircky slashes bug." | Assigned (20070614) | None (candidate not yet proposed) | View |
Page 19140 of 20943, showing 5 records out of 104715 total, starting on record 95696, ending on 95700