CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10493 | CVE-2004-2067 | Candidate | SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attackers to execute arbitrary SQL and bypass authentication via the (1) user, (2) password, or (3) crypted_password parameters. | Assigned (20050504) | None (candidate not yet proposed) | View | |
76029 | CVE-2014-8728 | Candidate | SQL injection vulnerability in the login page (login/login) in Subex ROC Fraud Management (aka Fraud Management System and FMS) 7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the ranger_user[name] parameter. | Assigned (20141110) | None (candidate not yet proposed) | View | |
10749 | CVE-2004-2323 | Candidate | DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to obtain sensitive information, including the SQL server username and password, via a GET request for source or configuration files such as Web.config. | Assigned (20050816) | None (candidate not yet proposed) | View | |
76285 | CVE-2014-8984 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20141118) | None (candidate not yet proposed) | View | |
11005 | CVE-2004-2579 | Candidate | ACLCHECK module in Novell iChain 2.3 allows attackers to bypass access control rules of an unspecified component via an unspecified attack vector involving a string that contains escape sequences represented with "overlong UTF-8 encoding." | Assigned (20051128) | None (candidate not yet proposed) | View |
Page 20719 of 20943, showing 5 records out of 104715 total, starting on record 103591, ending on 103595