CVE List

Id CVE No. Status Description Phase Votes Comments Actions
95747  CVE-2016-8927  Candidate  IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118540.  Assigned (20161025)  None (candidate not yet proposed)    View
30467  CVE-2008-0350  Candidate  admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to gain administrative privileges and make arbitrary configuration changes.  Assigned (20080117)  None (candidate not yet proposed)    View
96003  CVE-2016-9183  Candidate  In /framework/modules/ecommerce/controllers/orderController.php of Exponent CMS 2.4.0, untrusted input is passed into selectObjectsBySql. The method selectObjectsBySql of class mysqli_database uses the injectProof method to prevent SQL injection, but this filter can be bypassed easily: it only sanitizes user input if there are odd numbers of " or " characters. Impact is Information Disclosure.  Assigned (20161104)  None (candidate not yet proposed)    View
30723  CVE-2008-0606  Candidate  SQL injection vulnerability in index.php in the Shambo2 (com_shambo2) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter.  Assigned (20080205)  None (candidate not yet proposed)    View
96259  CVE-2016-9439  Candidate  An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Infinite recursion vulnerability in w3m allows remote attackers to cause a denial of service via a crafted HTML page.  Assigned (20161118)  None (candidate not yet proposed)    View

Page 896 of 20943, showing 5 records out of 104715 total, starting on record 4476, ending on 4480

Actions