CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
25593 | CVE-2007-2236 | Candidate | footer.php in PunBB 1.2.14 and earlier allows remote attackers to include local files in include/user/ via a cross-site scripting (XSS) attack, or via the pun_include tag, as demonstrated by use of admin_options.php to execute PHP code from an uploaded avatar file. | Assigned (20070425) | None (candidate not yet proposed) | View | |
91129 | CVE-2016-4310 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20160427) | None (candidate not yet proposed) | View | |
25849 | CVE-2007-2492 | Candidate | SQL injection vulnerability in index.php in the v4bJournal module for PostNuke allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a journal_comment action. | Assigned (20070503) | None (candidate not yet proposed) | View | |
91385 | CVE-2016-4566 | Candidate | Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack. | Assigned (20160507) | None (candidate not yet proposed) | View | |
26105 | CVE-2007-2748 | Candidate | The substr_count function in PHP 5.2.1 and earlier allows context-dependent attackers to obtain sensitive information via unspecified vectors, a different affected function than CVE-2007-1375. | Assigned (20070517) | None (candidate not yet proposed) | View |
Page 20421 of 20943, showing 5 records out of 104715 total, starting on record 102101, ending on 102105