CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
70713 | CVE-2014-3417 | Candidate | uPortal before 4.0.13.1 does not properly check the CONFIG permission, which allows remote authenticated users to configure portlets by leveraging the SUBSCRIBE permission for a portlet. | Assigned (20140507) | None (candidate not yet proposed) | View | |
17541 | CVE-2006-1437 | Candidate | UPOINT @1 Event Publisher stores sensitive information under the web document root with insufifcient access control, which allows remote attackers to read private comments via a direct request to eventpublisher.txt. | Assigned (20060328) | None (candidate not yet proposed) | View | |
60221 | CVE-2013-0274 | Candidate | upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long strings in UPnP responses, which allows remote attackers to cause a denial of service (application crash) by leveraging access to the local network. | Assigned (20121206) | None (candidate not yet proposed) | View | |
13939 | CVE-2005-2733 | Candidate | upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which could allow remote attackers to execute arbitrary code. | Assigned (20050829) | None (candidate not yet proposed) | View | |
50657 | CVE-2011-2745 | Candidate | upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict the file extensions of uploaded files, which allows remote authenticated users to upload a .php file, and consequently execute arbitrary PHP code, via a write_post action to the default URI under admin/. | Assigned (20110713) | None (candidate not yet proposed) | View |
Page 810 of 20943, showing 5 records out of 104715 total, starting on record 4046, ending on 4050