CVE List

Id CVE No. Status Description Phase Votes Comments Actions
51702  CVE-2011-3790  Candidate  Piwigo 2.1.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tools/metadata.php and certain other files.  Assigned (20110923)  None (candidate not yet proposed)    View
51958  CVE-2011-4046  Candidate  The Dell KACE K2000 System Deployment Appliance stores the recovery account password in cleartext within a PHP script, which allows context-dependent attackers to obtain sensitive information by examining script source code.  Assigned (20111013)  None (candidate not yet proposed)    View
52214  CVE-2011-4302  Candidate  mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the openssl_verify function, which allows remote attackers to bypass validation via a crafted certificate.  Assigned (20111104)  None (candidate not yet proposed)    View
52470  CVE-2011-4558  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20111128)  None (candidate not yet proposed)    View
52726  CVE-2011-4814  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) admin/boxes.php, (3) comm/clients.php, (4) commande/index.php; and the optioncss parameter to (5) admin/ihm.php and (6) user/home.php.  Assigned (20111213)  None (candidate not yet proposed)    View

Page 20217 of 20943, showing 5 records out of 104715 total, starting on record 101081, ending on 101085

Actions