CVE List

Id CVE No. Status Description Phase Votes Comments Actions
29960  CVE-2007-6603  Candidate  Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attackers to obtain the administrator username and password via a direct request to control/backup/backup.php, which generates a backup/dump/backup.sql file that can be downloaded via a direct request to control/downloadfile.php.  Assigned (20071231)  None (candidate not yet proposed)    View
95496  CVE-2016-8676  Candidate  The get_vlc2 function in get_bits.h in Libav 11.9 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted mp3 file. NOTE: this issue exists due to an incomplete fix for CVE-2016-8675.  Assigned (20161015)  None (candidate not yet proposed)    View
30216  CVE-2008-0099  Candidate  Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the searchtext parameter to search.php, and unspecified other vectors.  Assigned (20080107)  None (candidate not yet proposed)    View
95752  CVE-2016-8932  Candidate  IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.  Assigned (20161025)  None (candidate not yet proposed)    View
30472  CVE-2008-0355  Candidate  SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a section action, a different vector than CVE-2007-2866.  Assigned (20080118)  None (candidate not yet proposed)    View

Page 685 of 20943, showing 5 records out of 104715 total, starting on record 3421, ending on 3425

Actions