CVE List

Id CVE No. Status Description Phase Votes Comments Actions
24843  CVE-2007-1486  Candidate  PHP remote file inclusion vulnerability in template.class.php in Carbonize Lazarus Guestbook before 1.7.3 allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to admin.php, probably due to a dynamic variable evaluation vulnerability.  Assigned (20070316)  None (candidate not yet proposed)    View
90379  CVE-2016-3560  Candidate  Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality via vectors related to SDK, a different vulnerability than CVE-2016-3526 and CVE-2016-3529.  Assigned (20160317)  None (candidate not yet proposed)    View
25099  CVE-2007-1742  Candidate  suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root, which might allow local users to perform unauthorized operations on incorrect directories, as demonstrated using "html_backup" and "htmleditor" under an "html" directory. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."  Assigned (20070328)  None (candidate not yet proposed)    View
90635  CVE-2016-3816  Candidate  The MediaTek display driver in Android before 2016-07-05 on Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28402240.  Assigned (20160330)  None (candidate not yet proposed)    View
25355  CVE-2007-1998  Candidate  Direct static code injection vulnerability in HIOX Guest Book (HGB) 4.0 allows remote attackers to inject arbitrary PHP code via the Email field, which results in code execution through a direct request to gb.php.  Assigned (20070412)  None (candidate not yet proposed)    View

Page 915 of 20943, showing 5 records out of 104715 total, starting on record 4571, ending on 4575

Actions