CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7225 | CVE-2003-0398 | Candidate | Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, with the SSI EXEC feature enabled, allows remote attackers to execute arbitrary code via a text variable to a Vignette Application that is later displayed. | Assigned (20030610) | None (candidate not yet proposed) | View | |
4777 | CVE-2002-0385 | Candidate | Vignette Story Server 4.1 and 6.0 allows remote attackers to obtain sensitive information via a request that contains a large number of """ (double quote) and and ">" characters, which causes the TCL interpreter to crash and include stack data in the output. | Assigned (20020522) | None (candidate not yet proposed) | View | |
56770 | CVE-2012-3527 | Candidate | view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrary objects and possibly execute arbitrary PHP code via an unspecified parameter, related to a "missing signature (HMAC)." | Assigned (20120614) | None (candidate not yet proposed) | View | |
18567 | CVE-2006-2463 | Candidate | view_album.php in SelectaPix 1.31 and earlier allows remote attackers to obtain the installation path via a certain request, which displays the path in an error message, possibly due to an invalid or missing parameter. | Assigned (20060519) | None (candidate not yet proposed) | View | |
42588 | CVE-2010-0004 | Candidate | ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discover private root names by reading this view. | Assigned (20091214) | None (candidate not yet proposed) | View |
Page 545 of 20943, showing 5 records out of 104715 total, starting on record 2721, ending on 2725