CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40200  CVE-2009-2765  Candidate  httpd.c in httpd in the management GUI in DD-WRT 24 sp1, and other versions before build 12533, allows remote attackers to execute arbitrary commands via shell metacharacters in a request to a cgi-bin/ URI.  Assigned (20090814)  None (candidate not yet proposed)    View
40456  CVE-2009-3021  Candidate  Cross-site scripting (XSS) vulnerability in Site Calendar "mycaljp" plugin 2.0.0 through 2.0.6, as used in the Japanese extended package of Geeklog 1.5.0 through 1.5.2 and when distributed 20090629 or earlier, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20090831)  None (candidate not yet proposed)    View
40712  CVE-2009-3277  Candidate  DataVault.Tesla/Impl/TypeSystem/AssociationHelper.cs in datavault allows context-dependent attackers to cause a denial of service (CPU consumption) via an input string composed of an [ (open bracket) followed by many commas, related to a certain regular expression, aka a "ReDoS" vulnerability.  Assigned (20090921)  None (candidate not yet proposed)    View
40968  CVE-2009-3533  Candidate  SQL injection vulnerability in report.php in Meeting Room Booking System (MRBS) before 1.4.2 allows remote attackers to execute arbitrary SQL commands via the typematch parameter. NOTE: some of these details are obtained from third party information.  Assigned (20091002)  None (candidate not yet proposed)    View
41224  CVE-2009-3789  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in OpenDocMan 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the last_message parameter to (1) add.php, (2) toBePublished.php, (3) index.php, and (4) admin.php; the PATH_INFO to the default URI to (5) category.php, (6) department.php, (7) profile.php, (8) rejects.php, (9) search.php, (10) toBePublished.php, (11) user.php, and (12) view_file.php; and (13) the caller parameter in a Modify User action to user.php.  Assigned (20091026)  None (candidate not yet proposed)    View

Page 706 of 20943, showing 5 records out of 104715 total, starting on record 3526, ending on 3530

Actions