CVE List

Id CVE No. Status Description Phase Votes Comments Actions
17136  CVE-2006-1032  Candidate  Eval injection vulnerability in the decode function in rpc_decoder.php for phpRPC 0.7 and earlier, as used by runcms, exoops, and possibly other programs, allows remote attackers to execute arbitrary PHP code via the base64 tag.  Assigned (20060307)  None (candidate not yet proposed)    View
82672  CVE-2015-5395  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150706)  None (candidate not yet proposed)    View
17392  CVE-2006-1288  Candidate  Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060105 allow remote attackers to execute arbitrary SQL commands via cookies, related to (1) arrays of id/stamp pairs and (2) the keys in arrays of key/value pairs in ipsclass.php; (3) the topics variable in usercp.php; and the topicsread cookie in (4) topics.php, (5) search.php, and (6) forums.php.  Assigned (20060319)  None (candidate not yet proposed)    View
82928  CVE-2015-5651  Candidate  Cross-site scripting (XSS) vulnerability in Dotclear before 2.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20150724)  None (candidate not yet proposed)    View
17648  CVE-2006-1544  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in news.php in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) autorkomentarza and (2) tresckomentarza parameters.  Assigned (20060330)  None (candidate not yet proposed)    View

Page 19687 of 20943, showing 5 records out of 104715 total, starting on record 98431, ending on 98435

Actions