CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10750  CVE-2004-2324  Candidate  SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to modify the backend database via the (1) table and (2) field parameters in LinkClick.aspx.  Assigned (20050816)  None (candidate not yet proposed)    View
76286  CVE-2014-8985  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20141118)  None (candidate not yet proposed)    View
11006  CVE-2004-2580  Candidate  Cross-site scripting (XSS) vulnerability in Novell iChain 2.3 allows remote attackers to obtain login credentials via unspecified vectors.  Assigned (20051128)  None (candidate not yet proposed)    View
76542  CVE-2014-9241  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allow remote attackers to inject arbitrary web script or HTML via the (1) type parameter to report.php, (2) signature parameter in a do_editsig action to usercp.php, or (3) title parameter in the style-templates module in an edit_template action or (4) file parameter in the config-languages module in an edit action to admin/index.php.  Assigned (20141203)  None (candidate not yet proposed)    View
11262  CVE-2005-0056  Candidate  Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."  Assigned (20050111)  None (candidate not yet proposed)    View

Page 20798 of 20943, showing 5 records out of 104715 total, starting on record 103986, ending on 103990

Actions