CVE List

Id CVE No. Status Description Phase Votes Comments Actions
17932  CVE-2006-1828  Candidate  SQL injection vulnerability in php121language.php in PHP121 1.4 allows remote attackers to execute arbitrary SQL commands and execute arbitrary code via the sess_username variable, as set by the php121un HTTP COOKIE parameter, which is used in multiple files including php121login.php. NOTE: the code execution occurs because the SQL query results are used in an include statement.  Assigned (20060419)  None (candidate not yet proposed)    View
83468  CVE-2015-6191  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150814)  None (candidate not yet proposed)    View
18188  CVE-2006-2084  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in FarsiNews 2.5.3 Pro and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameters in (a) index.php, and the (3) mod parameter in (b) admin.php.  Assigned (20060428)  None (candidate not yet proposed)    View
83724  CVE-2015-6447  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150817)  None (candidate not yet proposed)    View
18444  CVE-2006-2340  Candidate  Cross-site scripting (XSS) vulnerability in PassMasterFlex and PassMasterFlexPlus (PassMasterFlex+) 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) username, (2) password, or (3) User-Agent HTTP header in the Hack Log.  Assigned (20060511)  None (candidate not yet proposed)    View

Page 986 of 20943, showing 5 records out of 104715 total, starting on record 4926, ending on 4930

Actions