CVE List

Id CVE No. Status Description Phase Votes Comments Actions
56821  CVE-2012-3578  Candidate  Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.1 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with a file with an executable extension followed by a safe extension, then accessing it via a direct request to the file in html/images.  Assigned (20120616)  None (candidate not yet proposed)    View
57077  CVE-2012-3834  Candidate  SQL injection vulnerability in forensics/base_qry_main.php in AlienVault Open Source Security Information Management (OSSIM) 3.1 allows remote authenticated users to execute arbitrary SQL commands via the time[0][0] parameter.  Assigned (20120703)  None (candidate not yet proposed)    View
57333  CVE-2012-4090  Candidate  The management interface in Cisco NX-OS on Nexus 7000 devices allows remote authenticated users to obtain sensitive configuration-file information by leveraging the network-operator role, aka Bug ID CSCti09089.  Assigned (20120731)  None (candidate not yet proposed)    View
57589  CVE-2012-4346  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20120816)  None (candidate not yet proposed)    View
57845  CVE-2012-4602  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in admin/code/tce_select_users_popup.php in Nicola Asuni TCExam before 11.3.009 allow remote attackers to inject arbitrary web script or HTML via the (1) cid or (2) uids parameter.  Assigned (20120822)  None (candidate not yet proposed)    View

Page 20135 of 20943, showing 5 records out of 104715 total, starting on record 100671, ending on 100675

Actions