CVE List

Id CVE No. Status Description Phase Votes Comments Actions
36346  CVE-2008-6229  Candidate  Cross-site scripting (XSS) vulnerability in the administrative interface in Drupal Content Construction Kit (CCK) 5.x before 5.x-1.10 and 6.x before 6.x-2.0, a module for Drupal, allows remote authenticated users with "administer content" permissions to inject arbitrary web script or HTML via (1) field labels and (2) content-type names.  Assigned (20090220)  None (candidate not yet proposed)    View
101882  CVE-2017-5062  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170102)  None (candidate not yet proposed)    View
36602  CVE-2008-6485  Candidate  SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery allows remote attackers to execute arbitrary SQL commands via the ctg parameter.  Assigned (20090318)  None (candidate not yet proposed)    View
102138  CVE-2017-5318  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170109)  None (candidate not yet proposed)    View
36858  CVE-2008-6741  Candidate  SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands by setting the db_character_set parameter to a multibyte character set such as big5, which causes the addslashes PHP function to produce a "" (backslash) sequence that does not quote the """ (single quote) character, as demonstrated via a manlabels action to index.php.  Assigned (20090421)  None (candidate not yet proposed)    View

Page 20497 of 20943, showing 5 records out of 104715 total, starting on record 102481, ending on 102485

Actions