CVE List

Id CVE No. Status Description Phase Votes Comments Actions
36084  CVE-2008-5967  Candidate  admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.  Assigned (20090126)  None (candidate not yet proposed)    View
101620  CVE-2017-4800  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161226)  None (candidate not yet proposed)    View
36340  CVE-2008-6223  Candidate  PHP remote file inclusion vulnerability in visualizza.php in Way Of The Warrior (WOTW) 5.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the plancia parameter to crea.php.  Assigned (20090220)  None (candidate not yet proposed)    View
101876  CVE-2017-5056  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170102)  None (candidate not yet proposed)    View
36596  CVE-2008-6479  Candidate  Cross-site request forgery (CSRF) vulnerability in the "change password" feature in the VZPP web interface for Parallels Virtuozzo 25.4.swsoft (build 3.0.0-25.4.swsoft) allows remote attackers to modify the password via a link or IMG tag to vz/cp/pwd.  Assigned (20090316)  None (candidate not yet proposed)    View

Page 20043 of 20943, showing 5 records out of 104715 total, starting on record 100211, ending on 100215

Actions