CVE List

Id CVE No. Status Description Phase Votes Comments Actions
24538  CVE-2007-1181  Candidate  WebAPP before 0.9.9.5 passes (1) Unused Informations and (2) the username through Edit Profile forms, which has unknown impact and attack vectors.  Assigned (20070228)  None (candidate not yet proposed)    View
24536  CVE-2007-1179  Candidate  WebAPP before 0.9.9.5 does not properly manage e-mail addresses in certain contexts related to (1) the Recommend feature, Email Article (2) senders and (3) recipients, (4) New User Approval, (5) Edit Profiles, (6) the Newsletter Subscription form, (7) the Recommend form, and (8) sending of articles, which has unknown impact, and remote attack vectors related to spam attacks and possibly other attacks.  Assigned (20070228)  None (candidate not yet proposed)    View
24534  CVE-2007-1177  Candidate  WebAPP before 0.9.9.5 does not properly filter certain characters in contexts related to (1) the query string, (2) Profiles, (3) the Forum Post icon field, (4) the Edit Profile, and (5) the Gallery, which has unknown impact and remote attack vectors, possibly related to cross-site scripting (XSS).  Assigned (20070228)  None (candidate not yet proposed)    View
24537  CVE-2007-1180  Candidate  WebAPP before 0.9.9.5 does not check referrers in certain forms, which might facilitate remote cross-site request forgery (CSRF) attacks or have other unknown impact.  Assigned (20070228)  None (candidate not yet proposed)    View
24535  CVE-2007-1178  Candidate  WebAPP before 0.9.9.5 does not check access in certain contexts related to (1) Calendar Administration, (2) Instant Messages Administration, and (3) the Image Uploader, which has unknown impact and attack vectors.  Assigned (20070228)  None (candidate not yet proposed)    View

Page 390 of 20943, showing 5 records out of 104715 total, starting on record 1946, ending on 1950

Actions