CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
96003 | CVE-2016-9183 | Candidate | In /framework/modules/ecommerce/controllers/orderController.php of Exponent CMS 2.4.0, untrusted input is passed into selectObjectsBySql. The method selectObjectsBySql of class mysqli_database uses the injectProof method to prevent SQL injection, but this filter can be bypassed easily: it only sanitizes user input if there are odd numbers of " or " characters. Impact is Information Disclosure. | Assigned (20161104) | None (candidate not yet proposed) | View | |
30723 | CVE-2008-0606 | Candidate | SQL injection vulnerability in index.php in the Shambo2 (com_shambo2) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter. | Assigned (20080205) | None (candidate not yet proposed) | View | |
96259 | CVE-2016-9439 | Candidate | An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Infinite recursion vulnerability in w3m allows remote attackers to cause a denial of service via a crafted HTML page. | Assigned (20161118) | None (candidate not yet proposed) | View | |
30979 | CVE-2008-0862 | Candidate | IBM Lotus Notes 6.0, 6.5, 7.0, and 8.0 signs an unsigned applet when a user forwards an email message to another user, which allows user-assisted remote attackers to bypass Execution Control List (ECL) protection. | Assigned (20080220) | None (candidate not yet proposed) | View | |
96515 | CVE-2016-9695 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20161201) | None (candidate not yet proposed) | View |
Page 661 of 20943, showing 5 records out of 104715 total, starting on record 3301, ending on 3305