NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
7515  CVE-2011-0451  Multiple cross-site scripting (XSS) vulnerabilities in (1) data/Smarty/templates/default/list.tpl and (2) data/Smarty/templates/default/campaign/bloc/cart_tag.tpl in EC-CUBE before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.    4.3  Medium  2017-01-07  2011-02-17  View
7514  CVE-2011-0450  The downloads manager in Opera before 11.01 on Windows does not properly determine the pathname of the filesystem-viewing application, which allows user-assisted remote attackers to execute arbitrary code via a crafted web site that hosts an executable file.    7.6  High  2017-01-07  2011-07-18  View
7513  CVE-2011-0449  actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.4, when a case-insensitive filesystem is used, does not properly implement filters associated with the list of available templates, which allows remote attackers to bypass intended access restrictions via an action name that uses an unintended case for alphabetic characters.    7.5  High  2017-01-07  2012-07-06  View
7512  CVE-2011-0448  Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the limit function specify integer values, which makes it easier for remote attackers to conduct SQL injection attacks via a non-numeric argument.    7.5  High  2017-01-07  2012-07-06  View
7511  CVE-2011-0447  Ruby on Rails 2.1.x, 2.2.x, and 2.3.x before 2.3.11, and 3.x before 3.0.4, does not properly validate HTTP requests that contain an X-Requested-With header, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via forged (1) AJAX or (2) API requests that leverage "combinations of browser plugins and HTTP redirects," a related issue to CVE-2011-0696.    6.8  Medium  2017-01-07  2012-07-06  View

Page 16170 of 17672, showing 5 records out of 88360 total, starting on record 80846, ending on 80850

Actions