CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
91130 | CVE-2016-4311 | Candidate | Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack the authentication of privileged users for requests that process XACML requests via an entitlement/eval-policy-submit.jsp request. | Assigned (20160427) | None (candidate not yet proposed) | View | |
25850 | CVE-2007-2493 | Candidate | PHP remote file inclusion vulnerability in faq.php in the FAQ & RULES 2.0.0 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. | Assigned (20070503) | None (candidate not yet proposed) | View | |
91386 | CVE-2016-4567 | Candidate | Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn." | Assigned (20160507) | None (candidate not yet proposed) | View | |
26106 | CVE-2007-2749 | Candidate | SQL injection vulnerability in question.php in FAQEngine 4.16.03 and earlier allows remote attackers to execute arbitrary SQL commands via the questionref parameter in a display action. | Assigned (20070517) | None (candidate not yet proposed) | View | |
91642 | CVE-2016-4823 | Candidate | Corega CG-WLBARAGM devices allow remote attackers to cause a denial of service (reboot) via unspecified vectors. | Assigned (20160517) | None (candidate not yet proposed) | View |
Page 20501 of 20943, showing 5 records out of 104715 total, starting on record 102501, ending on 102505