CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
36858 | CVE-2008-6741 | Candidate | SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands by setting the db_character_set parameter to a multibyte character set such as big5, which causes the addslashes PHP function to produce a "" (backslash) sequence that does not quote the """ (single quote) character, as demonstrated via a manlabels action to index.php. | Assigned (20090421) | None (candidate not yet proposed) | View | |
102394 | CVE-2017-5574 | Candidate | SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows unauthenticated users to execute arbitrary SQL commands via the activation parameter. | Assigned (20170123) | None (candidate not yet proposed) | View | |
37114 | CVE-2008-6997 | Candidate | Google Chrome 0.2.149.27 allows user-assisted remote attackers to cause a denial of service (browser crash) via an IMG tag with a long src attribute, which triggers the crash when the victim performs an "Inspect Element" action. | Assigned (20090817) | None (candidate not yet proposed) | View | |
102650 | CVE-2017-5830 | Candidate | Revive Adserver before 4.0.1 allows remote attackers to execute arbitrary code via serialized data in the cookies related to the delivery scripts. | Assigned (20170201) | None (candidate not yet proposed) | View | |
37370 | CVE-2008-7253 | Candidate | The default configuration of the web server in IBM Lotus Domino Server, possibly 6.0 through 8.0, enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398. | Assigned (20100125) | None (candidate not yet proposed) | View |
Page 20521 of 20943, showing 5 records out of 104715 total, starting on record 102601, ending on 102605