CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
23293 | CVE-2006-7189 | Candidate | Cross-site scripting (XSS) vulnerability in cgi-bin/admin/logs.cgi in web-app.net WebAPP before 20060403 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the Statistics Log Viewer. | Assigned (20070402) | None (candidate not yet proposed) | View | |
88829 | CVE-2016-2010 | Candidate | Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2011. | Assigned (20160122) | None (candidate not yet proposed) | View | |
23549 | CVE-2007-0192 | Candidate | Cross-site request forgery (CSRF) vulnerability in the save_main operation in the ad_perms section in admin.php in MKPortal allows remote attackers to modify privilege settings, as demonstrated using a getURL of admin.php within a .swf file contained in an IFRAME element, aka the "All Guests are Admin" attack. | Assigned (20070110) | None (candidate not yet proposed) | View | |
89085 | CVE-2016-2266 | Candidate | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none. | Assigned (20160208) | None (candidate not yet proposed) | View | |
23805 | CVE-2007-0448 | Candidate | The fopen function in PHP 5.2.0 does not properly handle invalid URI handlers, which allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files via a file path specified with an invalid URI, as demonstrated via the srpath URI. | Assigned (20070123) | None (candidate not yet proposed) | View |
Page 20739 of 20943, showing 5 records out of 104715 total, starting on record 103691, ending on 103695