CVE List

Id CVE No. Status Description Phase Votes Comments Actions
15602  CVE-2005-4398  Candidate  ** DISPUTED ** NOTE: the vendor has disputed this issue. Cross-site scripting (XSS) vulnerability in lemoon 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the q parameter. NOTE: the vendor has disputed this issue, saying "Sites are built on top of ASP.NET and you use lemoon core objects to easily manage and render content. The XSS vuln. you are referring to exists in one of our public sites built on lemoon i.e. a custom made site (as all sites are). The problem exists in a UserControl that handles form input and is in no way related to the lemoon core product."  Assigned (20051220)  None (candidate not yet proposed)    View
11148  CVE-2004-2722  Candidate  ** DISPUTED ** Nessus 2.0.10a stores account passwords in plaintext in .nessusrc files, which allows local users to obtain passwords. NOTE: the original researcher reports that the vendor has disputed this issue.  Assigned (20071006)  None (candidate not yet proposed)    View
58856  CVE-2012-5613  Candidate  ** DISPUTED ** MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who should not have administrative privileges, allows remote authenticated users to gain privileges by leveraging the FILE privilege to create files as the MySQL administrator. NOTE: the vendor disputes this issue, stating that this is only a vulnerability when the administrator does not follow recommendations in the product"s installation documentation. NOTE: it could be argued that this should not be included in CVE because it is a configuration issue.  Assigned (20121024)  None (candidate not yet proposed)    View
16473  CVE-2006-0369  Candidate  ** DISPUTED ** MySQL 5.0.18 allows local users with access to a VIEW to obtain sensitive information via the "SELECT * FROM information_schema.views;" query, which returns the query that created the VIEW. NOTE: this issue has been disputed by third parties, saying that the availability of the schema is a normal and sometimes desired aspect of database access.  Assigned (20060122)  None (candidate not yet proposed)    View
21141  CVE-2006-5037  Candidate  ** DISPUTED ** MySource Matrix after 3.8 allows remote attackers to use the application as an HTTP proxy server via a MIME encoded URL in the sq_content_src parameter to access arbitrary sites with the server"s IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that "The vendor does not consider this a vulnerability."  Assigned (20060927)  None (candidate not yet proposed)    View

Page 20908 of 20943, showing 5 records out of 104715 total, starting on record 104536, ending on 104540

Actions