CVE List

Id CVE No. Status Description Phase Votes Comments Actions
96003  CVE-2016-9183  Candidate  In /framework/modules/ecommerce/controllers/orderController.php of Exponent CMS 2.4.0, untrusted input is passed into selectObjectsBySql. The method selectObjectsBySql of class mysqli_database uses the injectProof method to prevent SQL injection, but this filter can be bypassed easily: it only sanitizes user input if there are odd numbers of " or " characters. Impact is Information Disclosure.  Assigned (20161104)  None (candidate not yet proposed)    View
30723  CVE-2008-0606  Candidate  SQL injection vulnerability in index.php in the Shambo2 (com_shambo2) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter.  Assigned (20080205)  None (candidate not yet proposed)    View
96259  CVE-2016-9439  Candidate  An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Infinite recursion vulnerability in w3m allows remote attackers to cause a denial of service via a crafted HTML page.  Assigned (20161118)  None (candidate not yet proposed)    View
30979  CVE-2008-0862  Candidate  IBM Lotus Notes 6.0, 6.5, 7.0, and 8.0 signs an unsigned applet when a user forwards an email message to another user, which allows user-assisted remote attackers to bypass Execution Control List (ECL) protection.  Assigned (20080220)  None (candidate not yet proposed)    View
96515  CVE-2016-9695  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161201)  None (candidate not yet proposed)    View

Page 661 of 20943, showing 5 records out of 104715 total, starting on record 3301, ending on 3305

Actions