CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
51691 | CVE-2011-3779 | Candidate | PhpHostBot 2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/create_acct.php and certain other files. | Assigned (20110923) | None (candidate not yet proposed) | View | |
51947 | CVE-2011-4035 | Candidate | Cross-site scripting (XSS) vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20111013) | None (candidate not yet proposed) | View | |
52203 | CVE-2011-4291 | Candidate | Moodle 2.0.x before 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted ratings operations. | Assigned (20111104) | None (candidate not yet proposed) | View | |
52459 | CVE-2011-4547 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in includes/templates/template_default/common/tpl_header_test_info.php in Zen Cart 1.3.9h, when debugging is enabled, might allow remote attackers to inject arbitrary web script or HTML via the (1) main_page parameter or (2) PATH_INFO, a different vulnerability than CVE-2011-4567. | Assigned (20111123) | None (candidate not yet proposed) | View | |
52715 | CVE-2011-4803 | Candidate | SQL injection vulnerability in wptouch/ajax.php in the WPTouch plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter. | Assigned (20111213) | None (candidate not yet proposed) | View |
Page 19342 of 20943, showing 5 records out of 104715 total, starting on record 96706, ending on 96710