CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11984  CVE-2005-0778  Candidate  PhotoPost PHP 5.0 RC3 does not fully verify that an uploaded file is an image file, which allows remote attackers to inject arbitrary Javascript by uploading non-image files with an image extension such as .gif.  Assigned (20050320)  None (candidate not yet proposed)    View
11985  CVE-2005-0779  Candidate  PlatinumFTP 1.0.18, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via multiple connection attempts with a (backslash) in the username.  Assigned (20050320)  None (candidate not yet proposed)    View
11986  CVE-2005-0780  Candidate  paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3) category.php, (4) file.php, (5) team.php, (6) license.php, (7) custom.php, (8) admins.php, or (9) backupdb.php, which reveal the path in a PHP error message.  Assigned (20050320)  None (candidate not yet proposed)    View
11987  CVE-2005-0781  Candidate  SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter to pafiledb.php.  Assigned (20050320)  None (candidate not yet proposed)    View
11988  CVE-2005-0782  Candidate  Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the start parameter to pafiledb.php.  Assigned (20050320)  None (candidate not yet proposed)    View

Page 1308 of 20943, showing 5 records out of 104715 total, starting on record 6536, ending on 6540

Actions