CVE List

Id CVE No. Status Description Phase Votes Comments Actions
47098  CVE-2010-4514  Candidate  Cross-site scripting (XSS) vulnerability in Install/InstallWizard.aspx in DotNetNuke 5.05.01 and 5.06.00 allows remote attackers to inject arbitrary web script or HTML via the __VIEWSTATE parameter. NOTE: some of these details are obtained from third party information.  Assigned (20101209)  None (candidate not yet proposed)    View
47354  CVE-2010-4770  Candidate  SQL injection vulnerability in index.php in CommodityRentals DVD Rentals Script allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a catalog action.  Assigned (20110323)  None (candidate not yet proposed)    View
47610  CVE-2010-5026  Candidate  SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter. NOTE: some of these details are obtained from third party information.  Assigned (20111102)  None (candidate not yet proposed)    View
47866  CVE-2010-5282  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in OpenText ECM (formerly Livelink ECM) 9.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) viewType and (2) sort parameters in a browse action to livelink/livelink; and the (3) nodeid, (4) setctx, and (5) support parameters to livelinkdav/nodes/OOB_DAVWindow.html.  Assigned (20121126)  None (candidate not yet proposed)    View
48122  CVE-2011-0210  Candidate  QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted sample tables in a movie file.  Assigned (20101223)  None (candidate not yet proposed)    View

Page 20531 of 20943, showing 5 records out of 104715 total, starting on record 102651, ending on 102655

Actions