CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11994  CVE-2005-0788  Candidate  LimeWire 4.1.2 through 4.5.6 allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutella GET request.  Assigned (20050320)  None (candidate not yet proposed)    View
11995  CVE-2005-0789  Candidate  Directory traversal vulnerability in LimeWire 3.9.6 through 4.6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in a magnet request.  Assigned (20050320)  None (candidate not yet proposed)    View
11996  CVE-2005-0790  Candidate  phpAdsNew 2.0.4 allows remote attackers to obtain sensitive information via a direct request to (1) lib-xmlrpcs.inc.php, (2) maintenance-activation.php, (3) maintenance-cleantables.php, (4) maintenance-autotargeting.php, (5) maintenance-reports.php, (6) phpads.php, (7) remotehtmlview.php, (8) click.php, (9) adcontent.php, which reveal the path in a PHP error message.  Assigned (20050320)  None (candidate not yet proposed)    View
11997  CVE-2005-0791  Candidate  Cross-site scripting (XSS) vulnerability in adframe.php in phpAdsNew 2.0.4-pr1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the refresh parameter.  Assigned (20050320)  None (candidate not yet proposed)    View
11998  CVE-2005-0792  Candidate  SQL injection vulnerability in ZPanel 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter to index.php or (2) page parameter to zpanel.php.  Assigned (20050320)  None (candidate not yet proposed)    View

Page 1310 of 20943, showing 5 records out of 104715 total, starting on record 6546, ending on 6550

Actions