CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11683 | CVE-2005-0477 | Candidate | Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to inject arbitrary web script via (1) a signature file or (2) a message post containing an IMG tag within a COLOR tag whose style is set to background:url. | Assigned (20050219) | None (candidate not yet proposed) | View | |
11684 | CVE-2005-0478 | Candidate | Multiple buffer overflows in TrackerCam 5.12 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) an HTTP request with a long User-Agent header or (2) a long argument to an arbitrary PHP script. | Assigned (20050219) | None (candidate not yet proposed) | View | |
11685 | CVE-2005-0479 | Candidate | Directory traversal vulnerability in ComGetLogFile.php3 for TrackerCam 5.12 and earlier allows remote attackers to read arbitrary files via ".." sequences and (1) "/" slash), (2) "" (backslash), or (3) hex-encoded characters in the fn parameter. | Assigned (20050219) | None (candidate not yet proposed) | View | |
11686 | CVE-2005-0480 | Candidate | Cross-site scripting (XSS) vulnerability in TrackerCam 5.12 and earlier allows remote attackers to inject arbitrary HTML or web script via the login request, which is recorded in a log file but not properly handled when the administrator views the log file. | Assigned (20050219) | None (candidate not yet proposed) | View | |
11687 | CVE-2005-0481 | Candidate | TrackerCam 5.12 and earlier allows remote attackers to read log files via the fn parameter in a direct request to the ComGetLogFile.php3 script. | Assigned (20050219) | None (candidate not yet proposed) | View |
Page 1189 of 20943, showing 5 records out of 104715 total, starting on record 5941, ending on 5945