CVE List

Id CVE No. Status Description Phase Votes Comments Actions
63228  CVE-2013-3281  Candidate  Cross-site scripting (XSS) vulnerability in EMC Documentum Webtop before 6.7 SP2 P07, Documentum WDK before 6.7 SP2 P07, Documentum Taskspace before 6.7 SP2 P07, Documentum Records Manager before 6.7 SP2 P07, Documentum Web Publisher before 6.5 SP7, Documentum Digital Asset Manager before 6.5 SP6, Documentum Administrator before 6.7 SP2 P07, and Documentum Capital Projects before 1.8 P01 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter in a URL.  Assigned (20130426)  None (candidate not yet proposed)    View
63484  CVE-2013-3537  Candidate  Multiple SQL injection vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id_post or (2) pg parameter.  Assigned (20130513)  None (candidate not yet proposed)    View
63740  CVE-2013-3793  Candidate  Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language.  Assigned (20130603)  None (candidate not yet proposed)    View
63996  CVE-2013-4049  Candidate  Unrestricted file upload vulnerability in IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 allows remote authenticated users to execute arbitrary code by uploading and accessing a JSP file.  Assigned (20130607)  None (candidate not yet proposed)    View
64252  CVE-2013-4305  Candidate  Cross-site scripting (XSS) vulnerability in contrib/example.php in the SyntaxHighlight GeSHi extension for MediaWiki, possibly as downloaded before September 2013, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.  Assigned (20130612)  None (candidate not yet proposed)    View

Page 20093 of 20943, showing 5 records out of 104715 total, starting on record 100461, ending on 100465

Actions