CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40965  CVE-2009-3530  Candidate  Cross-site scripting (XSS) vulnerability in storefront.php in RadScripts RadBids Gold 4 allows remote attackers to inject arbitrary web script or HTML via the mode parameter.  Assigned (20091002)  None (candidate not yet proposed)    View
41221  CVE-2009-3786  Candidate  Cross-site scripting (XSS) vulnerability in Organic Groups (OG) Vocabulary 5.x before 5.x-1.1 and 6.x before 6.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the group title.  Assigned (20091026)  None (candidate not yet proposed)    View
41477  CVE-2009-4042  Candidate  Cross-site scripting (XSS) vulnerability in the RootCandy theme 6.x before 6.x-1.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via the URI.  Assigned (20091120)  None (candidate not yet proposed)    View
41733  CVE-2009-4298  Candidate  The LAMS module (mod/lams) for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores the (1) username, (2) firstname, and (3) lastname fields within the user table, which allows attackers to obtain user account information via unknown vectors.  Assigned (20091211)  None (candidate not yet proposed)    View
41989  CVE-2009-4554  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Snitz Forums 2000 3.4.07 allow remote attackers to inject arbitrary web script or HTML via (1) the url parameter to pop_send_to_friend.asp, related to a crafted onload attribute of an IMG element; or (2) an onload attribute in a sound tag.  Assigned (20100104)  None (candidate not yet proposed)    View

Page 482 of 20943, showing 5 records out of 104715 total, starting on record 2406, ending on 2410

Actions