NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
8514  CVE-2011-1584  The updateFile function in inc/core/class.dc.media.php in the Media Manager in Dotclear before 2.2.3 does not properly restrict pathnames, which allows remote authenticated users to upload and execute arbitrary PHP code via the media_path or media_file parameter. NOTE: some of these details are obtained from third party information.    6.5  Medium  2017-01-07  2012-04-27  View
8770  CVE-2011-1890  Cross-site scripting (XSS) vulnerability in EditForm.aspx in Microsoft Office SharePoint Server 2010 and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via a post, aka "Editform Script Injection Vulnerability."    4.3  Medium  2017-01-07  2012-01-26  View
74562  CVE-2003-1492  Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a different domain via an HTTP request for a domain with an extra . (dot) at the end.    Medium  2017-01-03  2008-09-05  View
10306  CVE-2011-3734  Energine 2.3.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by core/framework/SimpleBuilder.class.php and certain other files.    Medium  2017-01-07  2012-03-12  View
10562  CVE-2011-4014  The TAC Case Attachment tool in Cisco Wireless Control System (WCS) 7.0 allows remote authenticated users to read arbitrary files under webnms/Temp/ via unspecified vectors, aka Bug ID CSCtq86807.    Medium  2017-01-07  2012-08-18  View

Page 2383 of 17672, showing 5 records out of 88360 total, starting on record 11911, ending on 11915

Actions