CVE List

Id CVE No. Status Description Phase Votes Comments Actions
21229  CVE-2006-5125  Candidate  Directory traversal vulnerability in window.php, possibly used by home.php, in Joshua Muheim phpMyWebmin 1.0 allows remote attackers to obtain sensitive information via a directory name in the target parameter, which triggers a directory listing through the opendir function.  Assigned (20061002)  None (candidate not yet proposed)    View
86765  CVE-2016-0469  Candidate  Unspecified vulnerability in the Oracle Retail MICROS C2 component in Oracle Retail Applications 9.89.0.0 allows local users to affect confidentiality via vectors related to POS.  Assigned (20151209)  None (candidate not yet proposed)    View
21485  CVE-2006-5381  Candidate  Contenido CMS stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain database credentials and other information via a direct request to (1) db_msql.inc, (2) db_mssql.inc, (3) db_mysqli.inc, (4) db_oci8.inc, (5) db_odbc.inc, (6) db_oracle.inc, (7) db_pgsql.inc, or (8) db_sybase.inc in the conlib/ directory.  Assigned (20061017)  None (candidate not yet proposed)    View
87021  CVE-2016-0725  Candidate  Cross-site scripting (XSS) vulnerability in the search_pagination function in course/classes/management_renderer.php in Moodle 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted search string.  Assigned (20151216)  None (candidate not yet proposed)    View
21741  CVE-2006-5637  Candidate  PHP remote file inclusion vulnerability in faq_reply.php in Faq Administrator 2.1b allows remote attackers to execute arbitrary PHP code via a URL in the email parameter.  Assigned (20061031)  None (candidate not yet proposed)    View

Page 19471 of 20943, showing 5 records out of 104715 total, starting on record 97351, ending on 97355

Actions