CVE List

Id CVE No. Status Description Phase Votes Comments Actions
36355  CVE-2008-6238  Candidate  Cross-site scripting (XSS) vulnerability in archive/savedqueries/savequeryfinish.html in OpenEdit Digital Asset Management (DAM) before 5.2014 allows remote attackers to inject arbitrary web script or HTML via the name parameter.  Assigned (20090223)  None (candidate not yet proposed)    View
101891  CVE-2017-5071  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170102)  None (candidate not yet proposed)    View
36611  CVE-2008-6494  Candidate  ASP User Engine.NET stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for users.mdb.  Assigned (20090319)  None (candidate not yet proposed)    View
102147  CVE-2017-5327  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170109)  None (candidate not yet proposed)    View
36867  CVE-2008-6750  Candidate  Unrestricted file upload vulnerability in add.php in FlexPHPDirectory 0.0.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in photo/.  Assigned (20090424)  None (candidate not yet proposed)    View

Page 299 of 20943, showing 5 records out of 104715 total, starting on record 1491, ending on 1495

Actions