CVE List

Id CVE No. Status Description Phase Votes Comments Actions
33786  CVE-2008-3669  Candidate  SQL injection vulnerability in comments.php in ZeeScripts Reviews Opinions Rating Posting Engine Web-Site PHP Script (aka ZeeReviews) allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.  Assigned (20080813)  None (candidate not yet proposed)    View
99322  CVE-2017-2502  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161201)  None (candidate not yet proposed)    View
34042  CVE-2008-3925  Candidate  Cross-site request forgery (CSRF) vulnerability in admin.php in Content Management Made Easy (CMME) 1.12 allows remote attackers to trigger the logout of an administrative user via a logout action.  Assigned (20080904)  None (candidate not yet proposed)    View
99578  CVE-2017-2758  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161201)  None (candidate not yet proposed)    View
34298  CVE-2008-4181  Candidate  Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for cPanel, when cPanel PHP Register Globals is enabled, allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) or absolute pathname in the fantasticopath parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.  Assigned (20080923)  None (candidate not yet proposed)    View

Page 20493 of 20943, showing 5 records out of 104715 total, starting on record 102461, ending on 102465

Actions