39177 |
CVE-2009-1742 |
Candidate |
code.php in PC4Arb Pc4 Uploader 9.0 and earlier makes it easier for remote attackers to conduct SQL injection attacks via crafted keyword sequences that are removed from a filter in the id parameter in a banner action, as demonstrated via the "UNIunionON" string, which is collapsed into "UNION" by the filter_sql function. |
Assigned (20090520) |
None (candidate not yet proposed) |
|
View
|
104713 |
CVE-2017-7893 |
Candidate |
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. |
Assigned (20170417) |
None (candidate not yet proposed) |
|
View
|
39433 |
CVE-2009-1998 |
Candidate |
Unspecified vulnerability in the Oracle Communications Order and Service Management component in Oracle Industry Applications 2.8.0, 6.2.0, 6.3.0, and 6.3.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. |
Assigned (20090608) |
None (candidate not yet proposed) |
|
View
|
39689 |
CVE-2009-2254 |
Candidate |
Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/sqlpatch.php, which allows remote attackers to execute arbitrary SQL commands via the query_string parameter in an execute action, in conjunction with a PATH_INFO of password_forgotten.php, related to a "SQL Execution" issue. |
Assigned (20090629) |
None (candidate not yet proposed) |
|
View
|
39945 |
CVE-2009-2510 |
Candidate |
The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, as used by Internet Explorer and other applications, does not properly handle a " |