CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
63485 | CVE-2013-3538 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id_post or (2) pg parameter. | Assigned (20130513) | None (candidate not yet proposed) | View | |
63741 | CVE-2013-3794 | Candidate | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Partition. | Assigned (20130603) | None (candidate not yet proposed) | View | |
63997 | CVE-2013-4050 | Candidate | Cross-site request forgery (CSRF) vulnerability in webadmin.nsf in Domino Web Administrator in IBM Domino 8.5 and 9.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. | Assigned (20130607) | None (candidate not yet proposed) | View | |
64253 | CVE-2013-4306 | Candidate | Cross-site request forgery (CSRF) vulnerability in api/ApiQueryCheckUser.php in the CheckUser extension for MediaWiki, possibly Checkuser before 2.3, allows remote attackers to hijack the authentication of arbitrary users for requests that "perform sensitive write actions" via unspecified vectors. | Assigned (20130612) | None (candidate not yet proposed) | View | |
64509 | CVE-2013-4562 | Candidate | The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via the state parameter. | Assigned (20130612) | None (candidate not yet proposed) | View |
Page 20783 of 20943, showing 5 records out of 104715 total, starting on record 103911, ending on 103915