CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
43525 | CVE-2010-0941 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in eTek Systems Hit Counter 2.0 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) inc/login.php, (3) admin/index.php, and (4) admin/forgot.php. | Assigned (20100308) | None (candidate not yet proposed) | View | |
43781 | CVE-2010-1197 | Candidate | Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, does not properly handle situations in which both "Content-Disposition: attachment" and "Content-Type: multipart" are present in HTTP headers, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an uploaded HTML document. | Assigned (20100330) | None (candidate not yet proposed) | View | |
44037 | CVE-2010-1453 | Candidate | Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the form_url parameter. | Assigned (20100415) | None (candidate not yet proposed) | View | |
44293 | CVE-2010-1709 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in upload.cgi in G5-Scripts Auto-Img-Gallery 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) user and (2) pass parameters. | Assigned (20100504) | None (candidate not yet proposed) | View | |
44549 | CVE-2010-1965 | Candidate | Unspecified vulnerability in HP Insight Orchestration for Windows before 6.1 allows remote attackers to read or modify data via unknown vectors. | Assigned (20100519) | None (candidate not yet proposed) | View |
Page 484 of 20943, showing 5 records out of 104715 total, starting on record 2416, ending on 2420