CVE List

Id CVE No. Status Description Phase Votes Comments Actions
63485  CVE-2013-3538  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id_post or (2) pg parameter.  Assigned (20130513)  None (candidate not yet proposed)    View
63741  CVE-2013-3794  Candidate  Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Partition.  Assigned (20130603)  None (candidate not yet proposed)    View
63997  CVE-2013-4050  Candidate  Cross-site request forgery (CSRF) vulnerability in webadmin.nsf in Domino Web Administrator in IBM Domino 8.5 and 9.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.  Assigned (20130607)  None (candidate not yet proposed)    View
64253  CVE-2013-4306  Candidate  Cross-site request forgery (CSRF) vulnerability in api/ApiQueryCheckUser.php in the CheckUser extension for MediaWiki, possibly Checkuser before 2.3, allows remote attackers to hijack the authentication of arbitrary users for requests that "perform sensitive write actions" via unspecified vectors.  Assigned (20130612)  None (candidate not yet proposed)    View
64509  CVE-2013-4562  Candidate  The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via the state parameter.  Assigned (20130612)  None (candidate not yet proposed)    View

Page 20783 of 20943, showing 5 records out of 104715 total, starting on record 103911, ending on 103915

Actions