CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
41221 | CVE-2009-3786 | Candidate | Cross-site scripting (XSS) vulnerability in Organic Groups (OG) Vocabulary 5.x before 5.x-1.1 and 6.x before 6.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the group title. | Assigned (20091026) | None (candidate not yet proposed) | View | |
41477 | CVE-2009-4042 | Candidate | Cross-site scripting (XSS) vulnerability in the RootCandy theme 6.x before 6.x-1.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via the URI. | Assigned (20091120) | None (candidate not yet proposed) | View | |
41733 | CVE-2009-4298 | Candidate | The LAMS module (mod/lams) for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores the (1) username, (2) firstname, and (3) lastname fields within the user table, which allows attackers to obtain user account information via unknown vectors. | Assigned (20091211) | None (candidate not yet proposed) | View | |
41989 | CVE-2009-4554 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Snitz Forums 2000 3.4.07 allow remote attackers to inject arbitrary web script or HTML via (1) the url parameter to pop_send_to_friend.asp, related to a crafted onload attribute of an IMG element; or (2) an onload attribute in a sound tag. | Assigned (20100104) | None (candidate not yet proposed) | View | |
42245 | CVE-2009-4810 | Candidate | The Secure Remote Password (SRP) implementation in Samhain before 2.5.4 does not check for a certain zero value where required by the protocol, which allows remote attackers to bypass authentication via crafted input. | Assigned (20100423) | None (candidate not yet proposed) | View |
Page 466 of 20943, showing 5 records out of 104715 total, starting on record 2326, ending on 2330