CVE List

Id CVE No. Status Description Phase Votes Comments Actions
23538  CVE-2007-0181  Candidate  PHP remote file inclusion vulnerability in include/common_function.php in magic photo storage website allows remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter.  Assigned (20070110)  None (candidate not yet proposed)    View
89074  CVE-2016-2255  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none.  Assigned (20160208)  None (candidate not yet proposed)    View
23794  CVE-2007-0437  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the sample Cache" Server Page (CSP) scripts in InterSystems Cache" allow remote attackers to inject arbitrary web script or HTML via (1) the TO parameter to loop.csp, (2) the VALUE parameter to cookie.csp, and (3) the PAGE parameter to showsource.csp in csp/samples/; and allow remote authenticated users to inject arbitrary web script or HTML via (4) the ERROR parameter to csp/samples/xmlclasseserror.csp, and unspecified vectors in (5) object.csp and (6) lotteryhistory.csp in csp/samples/.  Assigned (20070123)  None (candidate not yet proposed)    View
89330  CVE-2016-2511  Candidate  Cross-site scripting (XSS) vulnerability in WebSVN 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the path parameter to log.php.  Assigned (20160219)  None (candidate not yet proposed)    View
24050  CVE-2007-0693  Candidate  SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action. NOTE: this issue can produce resultant cross-site scripting (XSS).  Assigned (20070203)  None (candidate not yet proposed)    View

Page 19860 of 20943, showing 5 records out of 104715 total, starting on record 99296, ending on 99300

Actions