CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10488  CVE-2004-2062  Candidate  SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary SQL via the (1) thread_id, (2) parent_id, or (3) mode parameters.  Assigned (20050504)  None (candidate not yet proposed)    View
76024  CVE-2014-8723  Candidate  GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) plugins/InnovationPlugin.php, which reveals the installation path in an error message.  Assigned (20141110)  None (candidate not yet proposed)    View
10744  CVE-2004-2318  Candidate  The administrative interface (surgeftpmgr.cgi) for SurgeFTP Server 1.0b through 2.2k1 allows remote attackers to cause a temporary denial of service (crash) via requests with two percent (%) signs in the CMD parameter.  Assigned (20050816)  None (candidate not yet proposed)    View
76280  CVE-2014-8979  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20141118)  None (candidate not yet proposed)    View
11000  CVE-2004-2574  Candidate  Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to inject arbitrary web script or HTML via the date parameter in a calendar.uicalendar.planner menuaction.  Assigned (20051128)  None (candidate not yet proposed)    View

Page 20317 of 20943, showing 5 records out of 104715 total, starting on record 101581, ending on 101585

Actions