CVE List

Id CVE No. Status Description Phase Votes Comments Actions
47347  CVE-2010-4763  Candidate  The ACL-customer-status Ticket Type setting in Open Ticket Request System (OTRS) before 3.0.0-beta1 does not restrict the ticket options after an AJAX reload, which allows remote authenticated users to bypass intended ACL restrictions on the (1) Status, (2) Service, and (3) Queue via selections.  Assigned (20110318)  None (candidate not yet proposed)    View
47603  CVE-2010-5019  Candidate  SQL injection vulnerability in view_photo.php in 2daybiz Online Classified Script allows remote attackers to execute arbitrary SQL commands via the alb parameter.  Assigned (20111102)  None (candidate not yet proposed)    View
47859  CVE-2010-5275  Candidate  Cross-site scripting (XSS) vulnerability in memcache_admin in the Memcache module 5.x before 5.x-1.10 and 6.x before 6.x-1.6 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20121007)  None (candidate not yet proposed)    View
48115  CVE-2011-0203  Candidate  Absolute path traversal vulnerability in xftpd in the FTP Server component in Apple Mac OS X before 10.6.8 allows remote attackers to list arbitrary directories by using the root directory as the starting point of a recursive listing.  Assigned (20101223)  None (candidate not yet proposed)    View
48371  CVE-2011-0459  Candidate  Cross-site scripting (XSS) vulnerability in Cyber-Ark Password Vault Web Access (PVWA) 5.0 and earlier, 5.5 through 5.5 patch 4, and 6.0 through 6.0 patch 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20110114)  None (candidate not yet proposed)    View

Page 19968 of 20943, showing 5 records out of 104715 total, starting on record 99836, ending on 99840

Actions