CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9843  CVE-2004-1415  Candidate  SQL injection vulnerability in (1) disp_album.php and possibly (2) disp_img.php in 2Bgal 2.4 and 2.5.1 allows remote attackers to execute arbitrary SQL commands via the id_album parameter.  Assigned (20050212)  None (candidate not yet proposed)    View
9844  CVE-2004-1416  Candidate  pnxr3260.dll in the RealOne 2.0 build 6.0.11.868 browser plugin, as used in Internet Explorer, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embed tag.  Assigned (20050212)  None (candidate not yet proposed)    View
9845  CVE-2004-1417  Candidate  Cross-site scripting (XSS) vulnerability in login.php in PsychoStats 2.2.4 Beta and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter.  Assigned (20050212)  None (candidate not yet proposed)    View
9846  CVE-2004-1418  Candidate  Cross-site scripting (XSS) vulnerability in WPKontakt 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via an e-mail address, which is not quoted when a parsing error is generated.  Assigned (20050212)  None (candidate not yet proposed)    View
9847  CVE-2004-1419  Candidate  PHP remote file inclusion vulnerability in ZeroBoard 4.1pl4 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) _zb_path parameter to outlogin.php or (2) dir parameter to write.php to reference a URL on a remote web server that contains the code.  Assigned (20050212)  None (candidate not yet proposed)    View

Page 1141 of 20943, showing 5 records out of 104715 total, starting on record 5701, ending on 5705

Actions