CVE List

Id CVE No. Status Description Phase Votes Comments Actions
76028  CVE-2014-8727  Candidate  Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrator" or "Administrator" role to enumerate and delete arbitrary files via a .. (dot dot) in the name parameter to (1) tmui/Control/jspmap/tmui/system/archive/properties.jsp or (2) tmui/Control/form.  Assigned (20141110)  None (candidate not yet proposed)    View
10748  CVE-2004-2322  Candidate  SQL injection vulnerability in the (1) announce and (2) notes modules of phpWebSite before 0.9.3-2 allows remote attackers to execute arbitrary SQL queries, as demonstrated using the ANN_id parameter to the announce module.  Assigned (20050816)  None (candidate not yet proposed)    View
76284  CVE-2014-8983  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20141118)  None (candidate not yet proposed)    View
11004  CVE-2004-2578  Candidate  phpGroupWare before 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which allows remote attackers to sniff passwords.  Assigned (20051128)  None (candidate not yet proposed)    View
76540  CVE-2014-9239  Candidate  SQL injection vulnerability in the IPS Connect service (interface/ipsconnect/ipsconnect.php) in Invision Power Board (aka IPB or IP.Board) 3.3.x and 3.4.x through 3.4.7 before 20141114 allows remote attackers to execute arbitrary SQL commands via the id[] parameter.  Assigned (20141203)  None (candidate not yet proposed)    View

Page 20640 of 20943, showing 5 records out of 104715 total, starting on record 103196, ending on 103200

Actions