CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3836 | CVE-2001-1032 | Entry | admin.php in PHP-Nuke 5.2 and earlier, except 5.0RC1, does not check login credentials for upload operations, which allows remote attackers to copy and upload arbitrary files and read the PHP-Nuke configuration file by directly calling admin.php with an upload parameter and specifying the file to copy. | View | |||
69372 | CVE-2014-2077 | Candidate | Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 7.4.1 before 7.4.1-rev10 and 7.4.2 before 7.4.2-rev8 allows remote attackers to inject arbitrary web script or HTML via the subject of an email, involving "the aria "tags" for screenreaders at the top bar". | Assigned (20140219) | None (candidate not yet proposed) | View | |
69628 | CVE-2014-2333 | Candidate | Cross-site scripting (XSS) vulnerability in the Lazyest Gallery plugin before 1.1.21 for WordPress allows remote attackers to inject arbitrary web script or HTML via an EXIF tag. NOTE: some of these details are obtained from third party information. | Assigned (20140312) | None (candidate not yet proposed) | View | |
4348 | CVE-2001-1548 | Candidate | ZoneAlarm 2.1 through 2.6 and ZoneAlarm Pro 2.4 and 2.6 allows local users to bypass filtering via non-standard TCP packets created with non-Windows protocol adapters. | Assigned (20050714) | None (candidate not yet proposed) | View | |
69884 | CVE-2014-2589 | Candidate | Cross-site scripting (XSS) vulnerability in the Dashboard Backend service (stats/dashboard.jsp) in SonicWall Network Security Appliance (NSA) 2400 allows remote attackers to inject arbitrary web script or HTML via the sn parameter. | Assigned (20140323) | None (candidate not yet proposed) | View |
Page 20256 of 20943, showing 5 records out of 104715 total, starting on record 101276, ending on 101280