CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
18671 | CVE-2006-2567 | Candidate | Cross-site scripting (XSS) vulnerability in submit_article.php in Alstrasoft Article Manager Pro 1.6 allows remote attackers to inject arbitrary web script or HTML when submitting an article, as demonstrated using a javascript URI in a Cascading Style Sheets (CSS) property of a STYLE attribute of an element. | Assigned (20060524) | None (candidate not yet proposed) | View | |
84207 | CVE-2015-6930 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20150914) | None (candidate not yet proposed) | View | |
18927 | CVE-2006-2823 | Candidate | Katrien De Graeve a.shopKart 2.0 (aka ashopKart20) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) admin/scart.mdb and possibly (2) admin/scart97.mdb. | Assigned (20060605) | None (candidate not yet proposed) | View | |
84463 | CVE-2015-7186 | Candidate | Mozilla Firefox before 42.0 on Android allows user-assisted remote attackers to bypass the Same Origin Policy and trigger (1) a download or (2) cached profile-data reading via a file: URL in a saved HTML document. | Assigned (20150916) | None (candidate not yet proposed) | View | |
19183 | CVE-2006-3079 | Candidate | Cross-site scripting (XSS) vulnerability in index.cfm in SSPwiz Plus 1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter. | Assigned (20060619) | None (candidate not yet proposed) | View |
Page 19609 of 20943, showing 5 records out of 104715 total, starting on record 98041, ending on 98045