CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
40200 | CVE-2009-2765 | Candidate | httpd.c in httpd in the management GUI in DD-WRT 24 sp1, and other versions before build 12533, allows remote attackers to execute arbitrary commands via shell metacharacters in a request to a cgi-bin/ URI. | Assigned (20090814) | None (candidate not yet proposed) | View | |
40456 | CVE-2009-3021 | Candidate | Cross-site scripting (XSS) vulnerability in Site Calendar "mycaljp" plugin 2.0.0 through 2.0.6, as used in the Japanese extended package of Geeklog 1.5.0 through 1.5.2 and when distributed 20090629 or earlier, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20090831) | None (candidate not yet proposed) | View | |
40712 | CVE-2009-3277 | Candidate | DataVault.Tesla/Impl/TypeSystem/AssociationHelper.cs in datavault allows context-dependent attackers to cause a denial of service (CPU consumption) via an input string composed of an [ (open bracket) followed by many commas, related to a certain regular expression, aka a "ReDoS" vulnerability. | Assigned (20090921) | None (candidate not yet proposed) | View | |
40968 | CVE-2009-3533 | Candidate | SQL injection vulnerability in report.php in Meeting Room Booking System (MRBS) before 1.4.2 allows remote attackers to execute arbitrary SQL commands via the typematch parameter. NOTE: some of these details are obtained from third party information. | Assigned (20091002) | None (candidate not yet proposed) | View | |
41224 | CVE-2009-3789 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in OpenDocMan 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the last_message parameter to (1) add.php, (2) toBePublished.php, (3) index.php, and (4) admin.php; the PATH_INFO to the default URI to (5) category.php, (6) department.php, (7) profile.php, (8) rejects.php, (9) search.php, (10) toBePublished.php, (11) user.php, and (12) view_file.php; and (13) the caller parameter in a Modify User action to user.php. | Assigned (20091026) | None (candidate not yet proposed) | View |
Page 706 of 20943, showing 5 records out of 104715 total, starting on record 3526, ending on 3530