CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
47098 | CVE-2010-4514 | Candidate | Cross-site scripting (XSS) vulnerability in Install/InstallWizard.aspx in DotNetNuke 5.05.01 and 5.06.00 allows remote attackers to inject arbitrary web script or HTML via the __VIEWSTATE parameter. NOTE: some of these details are obtained from third party information. | Assigned (20101209) | None (candidate not yet proposed) | View | |
47354 | CVE-2010-4770 | Candidate | SQL injection vulnerability in index.php in CommodityRentals DVD Rentals Script allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a catalog action. | Assigned (20110323) | None (candidate not yet proposed) | View | |
47610 | CVE-2010-5026 | Candidate | SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter. NOTE: some of these details are obtained from third party information. | Assigned (20111102) | None (candidate not yet proposed) | View | |
47866 | CVE-2010-5282 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in OpenText ECM (formerly Livelink ECM) 9.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) viewType and (2) sort parameters in a browse action to livelink/livelink; and the (3) nodeid, (4) setctx, and (5) support parameters to livelinkdav/nodes/OOB_DAVWindow.html. | Assigned (20121126) | None (candidate not yet proposed) | View | |
48122 | CVE-2011-0210 | Candidate | QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted sample tables in a movie file. | Assigned (20101223) | None (candidate not yet proposed) | View |
Page 20531 of 20943, showing 5 records out of 104715 total, starting on record 102651, ending on 102655