CVE List

Id CVE No. Status Description Phase Votes Comments Actions
51707  CVE-2011-3795  Candidate  Podcast Generator 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by core/themes.php and certain other files.  Assigned (20110923)  None (candidate not yet proposed)    View
51963  CVE-2011-4051  Candidate  CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which allows remote attackers to execute arbitrary code via vectors related to creation of a file, loading a DLL, and process control.  Assigned (20111013)  None (candidate not yet proposed)    View
52219  CVE-2011-4307  Candidate  Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the section parameter.  Assigned (20111104)  None (candidate not yet proposed)    View
52475  CVE-2011-4563  Candidate  Cross-site scripting (XSS) vulnerability in index.php in JAKCMS 2.0.4.1, and possibly other versions before 2.2.6 2011-09-23, allows remote attackers to inject arbitrary web script or HTML via the userpost parameter in a PM request, related to tinymce. NOTE: some of these details are obtained from third party information.  Assigned (20111128)  None (candidate not yet proposed)    View
52731  CVE-2011-4819  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allow remote attackers to inject arbitrary web script or HTML via the uisesionid parameter to (1) maximo.jsp or (2) the default URI under ui/.  Assigned (20111214)  None (candidate not yet proposed)    View

Page 20612 of 20943, showing 5 records out of 104715 total, starting on record 103056, ending on 103060

Actions