CVE List

Id CVE No. Status Description Phase Votes Comments Actions
26089  CVE-2007-2732  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML via the (1) path parameter to view/search/; or the (2) companyname, (3) country, (4) email, (5) firstname, (6) middlename, (7) required, (8) surname, or (9) title parameter to view/supplynews/.  Assigned (20070516)  None (candidate not yet proposed)    View
91625  CVE-2016-4806  Candidate  Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access web server sensitive files.  Assigned (20160515)  None (candidate not yet proposed)    View
26345  CVE-2007-2988  Candidate  A certain admin script in Inout Meta Search Engine sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject arbitrary PHP code, as demonstrated by a request to admin/create_engine.php followed by a request to admin/generate_tabs.php.  Assigned (20070531)  None (candidate not yet proposed)    View
91881  CVE-2016-5062  Candidate  The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, which allows remote attackers to execute arbitrary Java code by registering MBeans.  Assigned (20160526)  None (candidate not yet proposed)    View
26601  CVE-2007-3244  Candidate  SQL injection vulnerability in bb-includes/formatting-functions.php in bbPress before 0.8.1 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors to forums/bb-edit.php, as demonstrated by a PRE element, aka the "quircky slashes bug."  Assigned (20070614)  None (candidate not yet proposed)    View

Page 19140 of 20943, showing 5 records out of 104715 total, starting on record 95696, ending on 95700

Actions