CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11700 | CVE-2005-0494 | Candidate | The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the password before performing changes, which allows remote attackers on the LAN to gain access via a direct POST request. | Assigned (20050221) | None (candidate not yet proposed) | View | |
11701 | CVE-2005-0495 | Candidate | Cross-site scripting (XSS) vulnerability in ZeroBoard allows remote attackers to inject arbitrary web script or HTML via the (1) sn1, (2) year, or (3) page parameter to zboard.php or (4) filename to view_image.php. | Assigned (20050221) | None (candidate not yet proposed) | View | |
11702 | CVE-2005-0496 | Candidate | Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands. | Assigned (20050221) | None (candidate not yet proposed) | View | |
11703 | CVE-2005-0497 | Candidate | ADP Elite System Max 9000 allows remote authenticated users to gain privileges by uploading a .profile that sets the ADPROOT environment variable to the root directory. | Assigned (20050221) | None (candidate not yet proposed) | View | |
11704 | CVE-2005-0498 | Candidate | Gigafast router (aka CompUSA router) allows remote attackers to gain sensitive information and bypass the login page via a direct request to backup.cfg, which reveals the administrator password in plaintext. | Assigned (20050221) | None (candidate not yet proposed) | View |
Page 1224 of 20943, showing 5 records out of 104715 total, starting on record 6116, ending on 6120