CVE List

Id CVE No. Status Description Phase Votes Comments Actions
36363  CVE-2008-6246  Candidate  SQL injection vulnerability in category.php in Scripts For Sites (SFS) EZ Webring allows remote attackers to execute arbitrary SQL commands via the cat parameter.  Assigned (20090223)  None (candidate not yet proposed)    View
101899  CVE-2017-5079  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170102)  None (candidate not yet proposed)    View
36619  CVE-2008-6502  Candidate  Directory traversal vulnerability in Pro Chat Rooms 3.0.2 allows remote authenticated users to select an arbitrary local PHP script as an avatar via a .. (dot dot) in the avatar parameter, and cause other users to execute this script by using sendData.php to send a message to (1) an individual user or (2) a room, leading to cross-site request forgery (CSRF), cross-site scripting (XSS), or other impacts.  Assigned (20090320)  None (candidate not yet proposed)    View
102155  CVE-2017-5335  Candidate  The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to cause a denial of service (out-of-memory error and crash) via a crafted OpenPGP certificate.  Assigned (20170110)  None (candidate not yet proposed)    View
36875  CVE-2008-6758  Candidate  Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to hijack the authentication of arbitrary users for requests that conduct persistent cross-site scripting (XSS) attacks via the cart_name parameter in a save action.  Assigned (20090428)  None (candidate not yet proposed)    View

Page 933 of 20943, showing 5 records out of 104715 total, starting on record 4661, ending on 4665

Actions