CVE List

Id CVE No. Status Description Phase Votes Comments Actions
52482  CVE-2011-4570  Candidate  SQL injection vulnerability in the Time Returns (com_timereturns) component 2.0 and possibly earlier versions for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a timereturns action to index.php.  Assigned (20111128)  None (candidate not yet proposed)    View
52738  CVE-2011-4826  Candidate  SQL injection vulnerability in session.php in AutoSec Tools V-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to process.php. NOTE: some of these details are obtained from third party information.  Assigned (20111214)  None (candidate not yet proposed)    View
52994  CVE-2011-5082  Candidate  Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field).  Assigned (20120319)  None (candidate not yet proposed)    View
53250  CVE-2012-0007  Candidate  The Microsoft Anti-Cross Site Scripting (AntiXSS) Library 3.x and 4.0 does not properly evaluate characters after the detection of a Cascading Style Sheets (CSS) escaped character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML input, aka "AntiXSS Library Bypass Vulnerability."  Assigned (20111109)  None (candidate not yet proposed)    View
53506  CVE-2012-0263  Candidate  monitor/index.php in op5 Monitor and op5 Appliance before 5.5.1 allows remote authenticated users to obtain sensitive information such as database and user credentials via error messages that are triggered by (1) a malformed hoststatustypes parameter to status/service/all or (2) a crafted request to config.  Assigned (20111221)  None (candidate not yet proposed)    View

Page 230 of 20943, showing 5 records out of 104715 total, starting on record 1146, ending on 1150

Actions