CVE List

Id CVE No. Status Description Phase Votes Comments Actions
15860  CVE-2005-4656  Candidate  SQL injection vulnerability in index.php in TClanPortal 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands, and retrieve all usernames and passwords, via the id parameter.  Assigned (20060116)  None (candidate not yet proposed)    View
81396  CVE-2015-4119  Candidate  Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijack the authentication of (1) administrators for requests that create an administrator account via a request to admin/users_edit.php or (2) arbitrary users for requests that conduct SQL injection attacks via the server parameter to monitor/show_sys_state.php.  Assigned (20150528)  None (candidate not yet proposed)    View
16116  CVE-2006-0012  Candidate  Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."  Assigned (20051109)  None (candidate not yet proposed)    View
81652  CVE-2015-4375  Candidate  The Chaos tool suite (ctools) module 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to obtain sensitive node titles via (1) an autocomplete search on custom entities without an access query tag or (2) leveraging knowledge of the ID of an entity.  Assigned (20150605)  None (candidate not yet proposed)    View
16372  CVE-2006-0268  Candidate  Unspecified vulnerability in the Security component of Oracle Database server 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB21.  Assigned (20060118)  None (candidate not yet proposed)    View

Page 20005 of 20943, showing 5 records out of 104715 total, starting on record 100021, ending on 100025

Actions