CVE List

Id CVE No. Status Description Phase Votes Comments Actions
86257  CVE-2015-8980  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170118)  None (candidate not yet proposed)    View
20977  CVE-2006-4873  Candidate  Jupiter CMS allows remote attackers to obtain sensitive information via a direct request for (1) includes/functions.php, (2) modules/register.php, (3) modules/poll.php, (4) modules/panel.php, (5) modules/pm.php, (6) modules/news.php, (7) modules/templates_change.php, (8) modules/users.php, (9) modules/misc.php, (10) modules/masspm.php, (11) modules/mass-email.php, (12) modules/main-nav.php, (13) modules/login.php, (14) modules/layout.php, (15) modules/hq.php, (16) modules/forum.php, (17) modules/forum-admin.php, (18) modules/events.php, (19) modules/emoticons.php, (20) modules/download.php, (21) modules/blocks.php, (22) modules/ban.php, (23) modules/badwords.php, (24) modules/ads.php, or (25) modules/admin.php, which reveals the installation path in various error messages. NOTE: The modules/online.php vector is already covered by CVE-2006-1679.  Assigned (20060919)  None (candidate not yet proposed)    View
86513  CVE-2016-0217  Candidate  IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to stored cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim"s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim"s cookie-based authentication credentials.  Assigned (20151208)  None (candidate not yet proposed)    View
21233  CVE-2006-5129  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in ph03y3nk just another flat file (JAF) CMS 4.0 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) the message parameter, and possibly other parameters, in module/shout/jafshout.php (aka the shoutbox); and (2) the message body in a forum post in module/forum/topicwin.php, related to the name, email, title, date, ldate, and lname variables.  Assigned (20061002)  None (candidate not yet proposed)    View
86769  CVE-2016-0473  Candidate  Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote authenticated users to affect integrity via unknown vectors related to Fluid Core.  Assigned (20151209)  None (candidate not yet proposed)    View

Page 19781 of 20943, showing 5 records out of 104715 total, starting on record 98901, ending on 98905

Actions