CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
36334 | CVE-2008-6217 | Candidate | Cross-site scripting (XSS) vulnerability in index.php in Extrakt Framework 0.7 allows remote attackers to inject arbitrary web script or HTML via the plugins[file][id] parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | Assigned (20090220) | None (candidate not yet proposed) | View | |
101870 | CVE-2017-5050 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170102) | None (candidate not yet proposed) | View | |
36590 | CVE-2008-6473 | Candidate | _blogadata/include/init_pass2.php in Blogator-script 0.95 allows remote attackers to change the password for arbitrary users via a modified "a" parameter with a "%" wildcard symbol in the b parameter. | Assigned (20090316) | None (candidate not yet proposed) | View | |
102126 | CVE-2017-5306 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170109) | None (candidate not yet proposed) | View | |
36846 | CVE-2008-6729 | Candidate | Multiple cross-site request forgery (CSRF) vulnerabilities in password.php in PHPmotion 2.1 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests that modify an account via the (1) password or (2) email_address parameter. | Assigned (20090420) | None (candidate not yet proposed) | View |
Page 19566 of 20943, showing 5 records out of 104715 total, starting on record 97826, ending on 97830