CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11488  CVE-2005-0282  Candidate  SQL injection vulnerability in member.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the uid parameter.  Assigned (20050210)  None (candidate not yet proposed)    View
11489  CVE-2005-0283  Candidate  Directory traversal vulnerability in index.php in QwikiWiki allows remote attackers to read arbitrary files via a .. (dot dot) and a %00 at the end of the filename in the page parameter.  Assigned (20050210)  None (candidate not yet proposed)    View
11490  CVE-2005-0284  Candidate  SQL injection vulnerability in addentry.php in Woltlab Burning Book 1.0 Gold, 1.1.1e, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the user-agent parameter.  Assigned (20050210)  None (candidate not yet proposed)    View
11491  CVE-2005-0285  Candidate  Webseries Payment Application does not properly restrict privileged operations, which allows remote authenticated users to gain privileges by directly accessing certain URLs.  Assigned (20050210)  None (candidate not yet proposed)    View
11492  CVE-2005-0286  Candidate  eMotion MediaPartner Web Server 5.0 and 5.1 allows remote attackers to obtain sensitive information via an HTTP request for a .bhtml file that contains a (1) . (dot) or (2) + (plus sign) at the end, which returns the source code for that file.  Assigned (20050210)  None (candidate not yet proposed)    View

Page 1126 of 20943, showing 5 records out of 104715 total, starting on record 5626, ending on 5630

Actions