CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
36995 | CVE-2008-6878 | Candidate | ** DISPUTED ** Directory traversal vulnerability in admin/includes/languages/english.php in Zen Cart 1.3.8a, 1.3.8, and earlier, when .htaccess is not supported, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the _SESSION[language] parameter. NOTE: the vendor disputes this issue, stating "at worst, the use of this vulnerability will reveal some local file paths." | Assigned (20090727) | None (candidate not yet proposed) | View | |
16837 | CVE-2006-0733 | Candidate | ** DISPUTED ** Cross-site scripting (XSS) vulnerability in WordPress 2.0.0 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes such as (1) onfocus and (2) onblur in the "author"s website" field. NOTE: followup comments to the researcher"s web log suggest that this issue is only exploitable by the same user who injects the XSS, so this might not be a vulnerability. | Assigned (20060216) | None (candidate not yet proposed) | View | |
73692 | CVE-2014-6392 | Candidate | ** DISPUTED ** Cross-site scripting (XSS) vulnerability in the Facebook app 14.0 and the Facebook Messenger app 10.0 for iOS allows remote attackers to inject arbitrary web script or HTML via a crafted filename extension that is improperly handled during MIME sniffing of chat traffic. NOTE: the vendor disputes the significance of this report, because the user must accept an interstitial warning before the HTML file content is rendered, and because the HTML content"s origin is a sandbox domain. | Assigned (20140915) | None (candidate not yet proposed) | View | |
68902 | CVE-2014-1607 | Candidate | ** DISPUTED ** Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject arbitrary web script or HTML via the year parameter to eventcalander/. NOTE: this issue has been disputed by the Drupal Security Team; it may be site-specific. If so, then this CVE will be REJECTed in the future. | Assigned (20140118) | None (candidate not yet proposed) | View | |
66304 | CVE-2013-6357 | Candidate | ** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST method, as demonstrated by a /manager/html/undeploy?path= URI. NOTE: the vendor disputes the significance of this report, stating that "the Apache Tomcat Security team has not accepted any reports of CSRF attacks against the Manager application ... as they require a reckless system administrator." | Assigned (20131103) | None (candidate not yet proposed) | View |
Page 20871 of 20943, showing 5 records out of 104715 total, starting on record 104351, ending on 104355