CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11700  CVE-2005-0494  Candidate  The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the password before performing changes, which allows remote attackers on the LAN to gain access via a direct POST request.  Assigned (20050221)  None (candidate not yet proposed)    View
11701  CVE-2005-0495  Candidate  Cross-site scripting (XSS) vulnerability in ZeroBoard allows remote attackers to inject arbitrary web script or HTML via the (1) sn1, (2) year, or (3) page parameter to zboard.php or (4) filename to view_image.php.  Assigned (20050221)  None (candidate not yet proposed)    View
11702  CVE-2005-0496  Candidate  Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands.  Assigned (20050221)  None (candidate not yet proposed)    View
11703  CVE-2005-0497  Candidate  ADP Elite System Max 9000 allows remote authenticated users to gain privileges by uploading a .profile that sets the ADPROOT environment variable to the root directory.  Assigned (20050221)  None (candidate not yet proposed)    View
11704  CVE-2005-0498  Candidate  Gigafast router (aka CompUSA router) allows remote attackers to gain sensitive information and bypass the login page via a direct request to backup.cfg, which reveals the administrator password in plaintext.  Assigned (20050221)  None (candidate not yet proposed)    View

Page 1224 of 20943, showing 5 records out of 104715 total, starting on record 6116, ending on 6120

Actions