CVE List

Id CVE No. Status Description Phase Votes Comments Actions
51695  CVE-2011-3783  Candidate  phpMyFAQ 2.6.13 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by lang/language_uk.php and certain other files.  Assigned (20110923)  None (candidate not yet proposed)    View
51951  CVE-2011-4039  Candidate  Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows user-assisted remote attackers to execute arbitrary code via a malformed file that triggers a "write access violation."  Assigned (20111013)  None (candidate not yet proposed)    View
52207  CVE-2011-4295  Candidate  The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.  Assigned (20111104)  None (candidate not yet proposed)    View
52463  CVE-2011-4551  Candidate  Cross-site scripting (XSS) vulnerability in tiki-cookie-jar.php in TikiWiki CMS/Groupware before 8.2 and LTS before 6.5 allows remote attackers to inject arbitrary web script or HTML via arbitrary parameters.  Assigned (20111127)  None (candidate not yet proposed)    View
52719  CVE-2011-4807  Candidate  Directory traversal vulnerability in main.php in phpAlbum 0.4.1.16 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the var1 parameter.  Assigned (20111213)  None (candidate not yet proposed)    View

Page 19651 of 20943, showing 5 records out of 104715 total, starting on record 98251, ending on 98255

Actions