CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
47347 | CVE-2010-4763 | Candidate | The ACL-customer-status Ticket Type setting in Open Ticket Request System (OTRS) before 3.0.0-beta1 does not restrict the ticket options after an AJAX reload, which allows remote authenticated users to bypass intended ACL restrictions on the (1) Status, (2) Service, and (3) Queue via selections. | Assigned (20110318) | None (candidate not yet proposed) | View | |
47603 | CVE-2010-5019 | Candidate | SQL injection vulnerability in view_photo.php in 2daybiz Online Classified Script allows remote attackers to execute arbitrary SQL commands via the alb parameter. | Assigned (20111102) | None (candidate not yet proposed) | View | |
47859 | CVE-2010-5275 | Candidate | Cross-site scripting (XSS) vulnerability in memcache_admin in the Memcache module 5.x before 5.x-1.10 and 6.x before 6.x-1.6 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20121007) | None (candidate not yet proposed) | View | |
48115 | CVE-2011-0203 | Candidate | Absolute path traversal vulnerability in xftpd in the FTP Server component in Apple Mac OS X before 10.6.8 allows remote attackers to list arbitrary directories by using the root directory as the starting point of a recursive listing. | Assigned (20101223) | None (candidate not yet proposed) | View | |
48371 | CVE-2011-0459 | Candidate | Cross-site scripting (XSS) vulnerability in Cyber-Ark Password Vault Web Access (PVWA) 5.0 and earlier, 5.5 through 5.5 patch 4, and 6.0 through 6.0 patch 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20110114) | None (candidate not yet proposed) | View |
Page 19968 of 20943, showing 5 records out of 104715 total, starting on record 99836, ending on 99840