CVE List

Id CVE No. Status Description Phase Votes Comments Actions
46073  CVE-2010-3489  Candidate  Cross-site scripting (XSS) vulnerability in netautor/napro4/home/login2.php in CMS Digital Workroom (formerly Netautor Professional) 5.5.0 allows remote attackers to inject arbitrary web script or HTML via the goback parameter.  Assigned (20100922)  None (candidate not yet proposed)    View
46329  CVE-2010-3745  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20101005)  None (candidate not yet proposed)    View
46585  CVE-2010-4001  Candidate  ** DISPUTED ** GMXRC.bash in Gromacs 4.5.1 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: CVE disputes this issue because the GMXLDLIB value is always added to the beginning of LD_LIBRARY_PATH at a later point in the script.  Assigned (20101019)  None (candidate not yet proposed)    View
46841  CVE-2010-4257  Candidate  SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote authenticated users to execute arbitrary SQL commands via the Send Trackbacks field.  Assigned (20101116)  None (candidate not yet proposed)    View
47097  CVE-2010-4513  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Zimplit CMS 3.0, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) file parameter in a load action to zimplit.php and (2) client parameter to English_manual_version_2.php.  Assigned (20101209)  None (candidate not yet proposed)    View

Page 19840 of 20943, showing 5 records out of 104715 total, starting on record 99196, ending on 99200

Actions