CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102395  CVE-2017-5575  Candidate  SQL injection vulnerability in inc/lib/Options.class.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the modules parameter.  Assigned (20170123)  None (candidate not yet proposed)    View
37115  CVE-2008-6998  Candidate  Stack-based buffer overflow in chrome/common/gfx/url_elider.cc in Google Chrome 0.2.149.27 and other versions before 0.2.149.29 might allow user-assisted remote attackers to execute arbitrary code via a link target (href attribute) with a large number of path elements, which triggers the overflow when the status bar is updated after the user hovers over the link.  Assigned (20090817)  None (candidate not yet proposed)    View
102651  CVE-2017-5831  Candidate  Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID.  Assigned (20170201)  None (candidate not yet proposed)    View
37371  CVE-2008-7254  Candidate  Directory traversal vulnerability in includes/template-loader.php in Irmin CMS (formerly Pepsi CMS) 0.5 and 0.6 BETA2, when register_globals is enabled, allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the _Root_Path parameter. NOTE: some of these details are obtained from third party information.  Assigned (20100407)  None (candidate not yet proposed)    View
102907  CVE-2017-6087  Candidate  EyesOfNetwork ("EON") 5.0 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the selected_events[] parameter in the (1) acknowledge, (2) delete, or (3) ownDisown function in module/monitoring_ged/ged_functions.php or the (4) module parameter to module/index.php.  Assigned (20170218)  None (candidate not yet proposed)    View

Page 20575 of 20943, showing 5 records out of 104715 total, starting on record 102871, ending on 102875

Actions