CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
56821 | CVE-2012-3578 | Candidate | Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.1 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with a file with an executable extension followed by a safe extension, then accessing it via a direct request to the file in html/images. | Assigned (20120616) | None (candidate not yet proposed) | View | |
57077 | CVE-2012-3834 | Candidate | SQL injection vulnerability in forensics/base_qry_main.php in AlienVault Open Source Security Information Management (OSSIM) 3.1 allows remote authenticated users to execute arbitrary SQL commands via the time[0][0] parameter. | Assigned (20120703) | None (candidate not yet proposed) | View | |
57333 | CVE-2012-4090 | Candidate | The management interface in Cisco NX-OS on Nexus 7000 devices allows remote authenticated users to obtain sensitive configuration-file information by leveraging the network-operator role, aka Bug ID CSCti09089. | Assigned (20120731) | None (candidate not yet proposed) | View | |
57589 | CVE-2012-4346 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20120816) | None (candidate not yet proposed) | View | |
57845 | CVE-2012-4602 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in admin/code/tce_select_users_popup.php in Nicola Asuni TCExam before 11.3.009 allow remote attackers to inject arbitrary web script or HTML via the (1) cid or (2) uids parameter. | Assigned (20120822) | None (candidate not yet proposed) | View |
Page 20135 of 20943, showing 5 records out of 104715 total, starting on record 100671, ending on 100675