CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13831 | CVE-2005-2625 | Candidate | Incomplete blacklist vulnerability in the checkBlacklist function in CPAINT allows remote attackers to execute arbitrary commands via the (1) ExecuteGlobal function or (2) GetRef statement, which is not included in the blacklist. | Assigned (20050819) | None (candidate not yet proposed) | View | |
79367 | CVE-2015-2090 | Candidate | SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 for Wordpress allows remote attackers to execute arbitrary SQL commands via the survey_id parameter in an ajax_survey action to wp-admin/admin-ajax.php. | Assigned (20150226) | None (candidate not yet proposed) | View | |
14087 | CVE-2005-2881 | Candidate | phpCommunityCalendar 4.0.3 allows remote attackers to bypass authentication and gain unauthorized access via a direct request to the admin directory. | Assigned (20050914) | None (candidate not yet proposed) | View | |
79623 | CVE-2015-2346 | Candidate | XML external entity (XXE) vulnerability in Huawei SEQ Analyst before V200R002C03LG0001CP0022 allows remote authenticated users to read arbitrary files via the req parameter. | Assigned (20150318) | None (candidate not yet proposed) | View | |
14343 | CVE-2005-3137 | Candidate | The (1) cfmailfilter and (2) cfcron.in files for cfengine 1.6.5 allow local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2005-2960. | Assigned (20051005) | None (candidate not yet proposed) | View |
Page 580 of 20943, showing 5 records out of 104715 total, starting on record 2896, ending on 2900