CVE List

Id CVE No. Status Description Phase Votes Comments Actions
23293  CVE-2006-7189  Candidate  Cross-site scripting (XSS) vulnerability in cgi-bin/admin/logs.cgi in web-app.net WebAPP before 20060403 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the Statistics Log Viewer.  Assigned (20070402)  None (candidate not yet proposed)    View
88829  CVE-2016-2010  Candidate  Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2011.  Assigned (20160122)  None (candidate not yet proposed)    View
23549  CVE-2007-0192  Candidate  Cross-site request forgery (CSRF) vulnerability in the save_main operation in the ad_perms section in admin.php in MKPortal allows remote attackers to modify privilege settings, as demonstrated using a getURL of admin.php within a .swf file contained in an IFRAME element, aka the "All Guests are Admin" attack.  Assigned (20070110)  None (candidate not yet proposed)    View
89085  CVE-2016-2266  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none.  Assigned (20160208)  None (candidate not yet proposed)    View
23805  CVE-2007-0448  Candidate  The fopen function in PHP 5.2.0 does not properly handle invalid URI handlers, which allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files via a file path specified with an invalid URI, as demonstrated via the srpath URI.  Assigned (20070123)  None (candidate not yet proposed)    View

Page 20739 of 20943, showing 5 records out of 104715 total, starting on record 103691, ending on 103695

Actions