CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10493  CVE-2004-2067  Candidate  SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters.  Assigned (20050504)  None (candidate not yet proposed)    View
76029  CVE-2014-8728  Candidate  SQL injection vulnerability in the login page (login/login) in Subex ROC Fraud Management (aka Fraud Management System and FMS) 7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the ranger_user[name] parameter.  Assigned (20141110)  None (candidate not yet proposed)    View
10749  CVE-2004-2323  Candidate  DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to obtain sensitive information, including the SQL server username and password, via a GET request for source or configuration files such as Web.config.  Assigned (20050816)  None (candidate not yet proposed)    View
76285  CVE-2014-8984  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20141118)  None (candidate not yet proposed)    View
11005  CVE-2004-2579  Candidate  ACLCHECK module in Novell iChain 2.3 allows attackers to bypass access control rules of an unspecified component via an unspecified attack vector involving a string that contains escape sequences represented with "overlong UTF-8 encoding."  Assigned (20051128)  None (candidate not yet proposed)    View

Page 20719 of 20943, showing 5 records out of 104715 total, starting on record 103591, ending on 103595

Actions