CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13831  CVE-2005-2625  Candidate  Incomplete blacklist vulnerability in the checkBlacklist function in CPAINT allows remote attackers to execute arbitrary commands via the (1) ExecuteGlobal function or (2) GetRef statement, which is not included in the blacklist.  Assigned (20050819)  None (candidate not yet proposed)    View
79367  CVE-2015-2090  Candidate  SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 for Wordpress allows remote attackers to execute arbitrary SQL commands via the survey_id parameter in an ajax_survey action to wp-admin/admin-ajax.php.  Assigned (20150226)  None (candidate not yet proposed)    View
14087  CVE-2005-2881  Candidate  phpCommunityCalendar 4.0.3 allows remote attackers to bypass authentication and gain unauthorized access via a direct request to the admin directory.  Assigned (20050914)  None (candidate not yet proposed)    View
79623  CVE-2015-2346  Candidate  XML external entity (XXE) vulnerability in Huawei SEQ Analyst before V200R002C03LG0001CP0022 allows remote authenticated users to read arbitrary files via the req parameter.  Assigned (20150318)  None (candidate not yet proposed)    View
14343  CVE-2005-3137  Candidate  The (1) cfmailfilter and (2) cfcron.in files for cfengine 1.6.5 allow local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2005-2960.  Assigned (20051005)  None (candidate not yet proposed)    View

Page 580 of 20943, showing 5 records out of 104715 total, starting on record 2896, ending on 2900

Actions