CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
38665 | CVE-2009-1230 | Candidate | Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated administrators to inject arbitrary PHP code into config.php via the recent parameter in a config change action. | Assigned (20090402) | None (candidate not yet proposed) | View | |
104201 | CVE-2017-7381 | Candidate | The doc/PdfPage.cpp:609:23 code in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document. | Assigned (20170331) | None (candidate not yet proposed) | View | |
38921 | CVE-2009-1486 | Candidate | Directory traversal vulnerability in pmscript.php in Flatchat 3.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the with parameter. | Assigned (20090429) | None (candidate not yet proposed) | View | |
104457 | CVE-2017-7637 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170410) | None (candidate not yet proposed) | View | |
39177 | CVE-2009-1742 | Candidate | code.php in PC4Arb Pc4 Uploader 9.0 and earlier makes it easier for remote attackers to conduct SQL injection attacks via crafted keyword sequences that are removed from a filter in the id parameter in a banner action, as demonstrated via the "UNIunionON" string, which is collapsed into "UNION" by the filter_sql function. | Assigned (20090520) | None (candidate not yet proposed) | View |
Page 778 of 20943, showing 5 records out of 104715 total, starting on record 3886, ending on 3890