CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11855  CVE-2005-0649  Candidate  Pixel-Apes SafeHTML before 1.2.1 allows remote attackers to bypass cross-site scripting (XSS) protection via "hexadecimal HTML entities."  Assigned (20050304)  None (candidate not yet proposed)    View
11856  CVE-2005-0650  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in ProjectBB 0.4.5.1 allow remote attackers to inject arbitrary web script or HTML via (1) the pages parameter to divers.php (incorrectly referred to as "drivers.php" by some sources), (2) in the search feature text area, (3) forum name, (4) site name or (5) the maximum avatar size in the option section, (5) new category or (6) new forum fields in the forum section.  Assigned (20050304)  None (candidate not yet proposed)    View
11857  CVE-2005-0651  Candidate  Multiple SQL injection vulnerabilities in ProjectBB 0.4.5.1 allow remote attackers to execute arbitrary SQL commands via (1) liste or (2) desc parameters to divers.php (incorrectly referred to as "drivers.php" by some sources), (3) the search feature text area, (4) post name in the post creation feature, (5) City, (6) Homepage, (7) ICQ, (8) AOL, (9) Yahoo!, (10) MSN, or (11) e-mail fields in the profile feature or (12) the new field in the moderator section.  Assigned (20050304)  None (candidate not yet proposed)    View
11858  CVE-2005-0652  Candidate  Unknown vulnerability in HP OpenVMS VAX 7.x and 6.x and OpenVMS Alpha 7.x or 6.x allows local users to access privileged files.  Assigned (20050307)  None (candidate not yet proposed)    View
11859  CVE-2005-0653  Candidate  phpMyAdmin 2.6.1 does not properly grant permissions on tables with an underscore in the name, which grants remote authenticated users more privileges than intended.  Assigned (20050307)  None (candidate not yet proposed)    View

Page 1266 of 20943, showing 5 records out of 104715 total, starting on record 6326, ending on 6330

Actions