CVE List

Id CVE No. Status Description Phase Votes Comments Actions
51727  CVE-2011-3815  Candidate  WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by js/calendar.php and certain other files.  Assigned (20110923)  None (candidate not yet proposed)    View
55038  CVE-2012-1795  Candidate  webglimpse.cgi in Webglimpse before 2.20.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter, as exploited in the wild in March 2012.  Assigned (20120320)  None (candidate not yet proposed)    View
68117  CVE-2014-0708  Candidate  WebEx Meeting Center in Cisco WebEx Business Suite does not properly compose URLs for HTTP GET requests, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) a browser"s history, aka Bug ID CSCul98272.  Assigned (20140102)  None (candidate not yet proposed)    View
19527  CVE-2006-3423  Candidate  WebEx Downloader ActiveX Control and WebEx Downloader Java before 2.1.0.0 do not validate downloaded components, which allows remote attackers to execute arbitrary code via a website that activates the GpcUrlRoot and GpcIniFileName ActiveX controls to cause the client to download a DLL file.  Assigned (20060706)  None (candidate not yet proposed)    View
59057  CVE-2012-5814  Candidate  Weberknecht, as used in GitHub Gaug.es and other products, does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.  Assigned (20121104)  None (candidate not yet proposed)    View

Page 382 of 20943, showing 5 records out of 104715 total, starting on record 1906, ending on 1910

Actions