CVE List

Id CVE No. Status Description Phase Votes Comments Actions
43525  CVE-2010-0941  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in eTek Systems Hit Counter 2.0 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) inc/login.php, (3) admin/index.php, and (4) admin/forgot.php.  Assigned (20100308)  None (candidate not yet proposed)    View
43781  CVE-2010-1197  Candidate  Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, does not properly handle situations in which both "Content-Disposition: attachment" and "Content-Type: multipart" are present in HTTP headers, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an uploaded HTML document.  Assigned (20100330)  None (candidate not yet proposed)    View
44037  CVE-2010-1453  Candidate  Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the form_url parameter.  Assigned (20100415)  None (candidate not yet proposed)    View
44293  CVE-2010-1709  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in upload.cgi in G5-Scripts Auto-Img-Gallery 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) user and (2) pass parameters.  Assigned (20100504)  None (candidate not yet proposed)    View
44549  CVE-2010-1965  Candidate  Unspecified vulnerability in HP Insight Orchestration for Windows before 6.1 allows remote attackers to read or modify data via unknown vectors.  Assigned (20100519)  None (candidate not yet proposed)    View

Page 484 of 20943, showing 5 records out of 104715 total, starting on record 2416, ending on 2420

Actions