CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
36084 | CVE-2008-5967 | Candidate | admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root. | Assigned (20090126) | None (candidate not yet proposed) | View | |
101620 | CVE-2017-4800 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20161226) | None (candidate not yet proposed) | View | |
36340 | CVE-2008-6223 | Candidate | PHP remote file inclusion vulnerability in visualizza.php in Way Of The Warrior (WOTW) 5.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the plancia parameter to crea.php. | Assigned (20090220) | None (candidate not yet proposed) | View | |
101876 | CVE-2017-5056 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170102) | None (candidate not yet proposed) | View | |
36596 | CVE-2008-6479 | Candidate | Cross-site request forgery (CSRF) vulnerability in the "change password" feature in the VZPP web interface for Parallels Virtuozzo 25.4.swsoft (build 3.0.0-25.4.swsoft) allows remote attackers to modify the password via a link or IMG tag to vz/cp/pwd. | Assigned (20090316) | None (candidate not yet proposed) | View |
Page 20043 of 20943, showing 5 records out of 104715 total, starting on record 100211, ending on 100215