CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
51727 | CVE-2011-3815 | Candidate | WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by js/calendar.php and certain other files. | Assigned (20110923) | None (candidate not yet proposed) | View | |
55038 | CVE-2012-1795 | Candidate | webglimpse.cgi in Webglimpse before 2.20.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter, as exploited in the wild in March 2012. | Assigned (20120320) | None (candidate not yet proposed) | View | |
68117 | CVE-2014-0708 | Candidate | WebEx Meeting Center in Cisco WebEx Business Suite does not properly compose URLs for HTTP GET requests, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) a browser"s history, aka Bug ID CSCul98272. | Assigned (20140102) | None (candidate not yet proposed) | View | |
19527 | CVE-2006-3423 | Candidate | WebEx Downloader ActiveX Control and WebEx Downloader Java before 2.1.0.0 do not validate downloaded components, which allows remote attackers to execute arbitrary code via a website that activates the GpcUrlRoot and GpcIniFileName ActiveX controls to cause the client to download a DLL file. | Assigned (20060706) | None (candidate not yet proposed) | View | |
59057 | CVE-2012-5814 | Candidate | Weberknecht, as used in GitHub Gaug.es and other products, does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | Assigned (20121104) | None (candidate not yet proposed) | View |
Page 382 of 20943, showing 5 records out of 104715 total, starting on record 1906, ending on 1910