CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40963  CVE-2009-3528  Candidate  SQL injection vulnerability in Profile.php in MyMsg 1.0.3 allows remote authenticated users to execute arbitrary SQL commands via the uid parameter in a show action.  Assigned (20091002)  None (candidate not yet proposed)    View
41219  CVE-2009-3784  Candidate  Open redirect vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.  Assigned (20091026)  None (candidate not yet proposed)    View
41475  CVE-2009-4040  Candidate  Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.0.17 and 2.5.x before 2.5.2, when used with Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the search page.  Assigned (20091120)  None (candidate not yet proposed)    View
41731  CVE-2009-4296  Candidate  SQL injection vulnerability in the Taxonomy Timer module 5.x-1.8 and earlier and 6.x-alpha1 and earlier for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.  Assigned (20091211)  None (candidate not yet proposed)    View
41987  CVE-2009-4552  Candidate  Cross-site scripting (XSS) vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.  Assigned (20100104)  None (candidate not yet proposed)    View

Page 305 of 20943, showing 5 records out of 104715 total, starting on record 1521, ending on 1525

Actions