CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11488 | CVE-2005-0282 | Candidate | SQL injection vulnerability in member.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the uid parameter. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11489 | CVE-2005-0283 | Candidate | Directory traversal vulnerability in index.php in QwikiWiki allows remote attackers to read arbitrary files via a .. (dot dot) and a %00 at the end of the filename in the page parameter. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11490 | CVE-2005-0284 | Candidate | SQL injection vulnerability in addentry.php in Woltlab Burning Book 1.0 Gold, 1.1.1e, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the user-agent parameter. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11491 | CVE-2005-0285 | Candidate | Webseries Payment Application does not properly restrict privileged operations, which allows remote authenticated users to gain privileges by directly accessing certain URLs. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11492 | CVE-2005-0286 | Candidate | eMotion MediaPartner Web Server 5.0 and 5.1 allows remote attackers to obtain sensitive information via an HTTP request for a .bhtml file that contains a (1) . (dot) or (2) + (plus sign) at the end, which returns the source code for that file. | Assigned (20050210) | None (candidate not yet proposed) | View |
Page 1126 of 20943, showing 5 records out of 104715 total, starting on record 5626, ending on 5630