CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
41978 | CVE-2009-4543 | Candidate | PHP remote file inclusion vulnerability in index.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to execute arbitrary PHP code via a URL in the lng parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences. | Assigned (20100104) | None (candidate not yet proposed) | View | |
42234 | CVE-2009-4799 | Candidate | Diskos CMS 6.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) artikler_prod.mdb or (2) medlemmer.mdb. | Assigned (20100422) | None (candidate not yet proposed) | View | |
42490 | CVE-2009-5055 | Candidate | Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on the basis of single-digit substrings of the CustomerID value, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by visiting a ticket, as demonstrated by leveraging the CustomerID 12 account to read tickets that should be available only to CustomerID 1 or CustomerID 2. | Assigned (20110318) | None (candidate not yet proposed) | View | |
42746 | CVE-2010-0162 | Candidate | Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly support the application/octet-stream content type as a protection mechanism against execution of web script in certain circumstances involving SVG and the EMBED element, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via an embedded SVG document. | Assigned (20100106) | None (candidate not yet proposed) | View | |
43002 | CVE-2010-0418 | Candidate | The web interface in chumby one before 1.0.4 and chumby classic before 1.7.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a request. | Assigned (20100127) | None (candidate not yet proposed) | View |
Page 20527 of 20943, showing 5 records out of 104715 total, starting on record 102631, ending on 102635