CVE List

Id CVE No. Status Description Phase Votes Comments Actions
18671  CVE-2006-2567  Candidate  Cross-site scripting (XSS) vulnerability in submit_article.php in Alstrasoft Article Manager Pro 1.6 allows remote attackers to inject arbitrary web script or HTML when submitting an article, as demonstrated using a javascript URI in a Cascading Style Sheets (CSS) property of a STYLE attribute of an element.  Assigned (20060524)  None (candidate not yet proposed)    View
84207  CVE-2015-6930  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150914)  None (candidate not yet proposed)    View
18927  CVE-2006-2823  Candidate  Katrien De Graeve a.shopKart 2.0 (aka ashopKart20) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) admin/scart.mdb and possibly (2) admin/scart97.mdb.  Assigned (20060605)  None (candidate not yet proposed)    View
84463  CVE-2015-7186  Candidate  Mozilla Firefox before 42.0 on Android allows user-assisted remote attackers to bypass the Same Origin Policy and trigger (1) a download or (2) cached profile-data reading via a file: URL in a saved HTML document.  Assigned (20150916)  None (candidate not yet proposed)    View
19183  CVE-2006-3079  Candidate  Cross-site scripting (XSS) vulnerability in index.cfm in SSPwiz Plus 1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter.  Assigned (20060619)  None (candidate not yet proposed)    View

Page 19609 of 20943, showing 5 records out of 104715 total, starting on record 98041, ending on 98045

Actions