CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40970  CVE-2009-3535  Candidate  Directory traversal vulnerability in image.php in Clear Content 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter. NOTE: the researcher also suggests an analogous PHP remote file inclusion vulnerability, but this may be incorrect.  Assigned (20091002)  None (candidate not yet proposed)    View
41226  CVE-2009-3791  Candidate  Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.5.3 allows attackers to cause a denial of service (resource exhaustion) via unknown vectors.  Assigned (20091026)  None (candidate not yet proposed)    View
41482  CVE-2009-4047  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in PHD Help Desk 1.43 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to area.php; the (2) pagina, (3) sentido, (4) q_registros, and (5) orden parameters to area.php; (6) the q_registros parameter to solic_display.php; (7) the PATH_INFO to area_list.php; (8) the q_registros parameter to area_list.php; (9) the PATH_INFO to atributo.php; the (10) pagina, (11) q_registros, and (12) orden parameters to atributo_list.php; (13) an arbitrary parameter name beginning with "sentido" to atributo_list.php; and (14) the PATH_INFO to caso_insert.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20091123)  None (candidate not yet proposed)    View
41738  CVE-2009-4303  Candidate  Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers to obtain sensitive information.  Assigned (20091211)  None (candidate not yet proposed)    View
41994  CVE-2009-4559  Candidate  Cross-site scripting (XSS) vulnerability in the Submitted By module 6.x before 6.x-1.3 for Drupal allows remote authenticated users, with "administer content types" privileges, to inject arbitrary web script or HTML via an input string for "submitted by" text.  Assigned (20100104)  None (candidate not yet proposed)    View

Page 867 of 20943, showing 5 records out of 104715 total, starting on record 4331, ending on 4335

Actions