CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12134 | CVE-2005-0928 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 5.x allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) password, (3) ppuser, (4) sort, or (5) si parameters to showgallery.php, the (6) ppuser, (7) sort, or (8) si parameters to showmembers.php, or (9) the photo parameter to slideshow.php. | Assigned (20050329) | None (candidate not yet proposed) | View | |
12135 | CVE-2005-0929 | Candidate | SQL injection vulnerability in PhotoPost PHP Pro 5.x may allow remote attackers to execute arbitrary SQL commands via (1) the sl parameter to showmembers.php or (2) the photo parameter to showphoto.php. | Assigned (20050329) | None (candidate not yet proposed) | View | |
6035 | CVE-2002-1651 | Candidate | Cross-site scripting (XSS) vulnerability in Verity Search97 allows remote attackers to insert arbitrary web content and steal sensitive information from other clients, possibly due to certain error messages from template pages that use the (1) vformat or (2) vfilter functions. | Assigned (20050329) | None (candidate not yet proposed) | View | |
6036 | CVE-2002-1652 | Candidate | Buffer overflow in cgicso.c for cgiemail 1.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long query parameter. | Assigned (20050329) | None (candidate not yet proposed) | View | |
6037 | CVE-2002-1653 | Candidate | Farm9 Cryptcat, when started in server mode with the -e option, does not enable encryption, which allows clients to communicate without encryption despite intended configuration, and may allow remote attackers to sniff sensitive information. | Assigned (20050329) | None (candidate not yet proposed) | View |
Page 1350 of 20943, showing 5 records out of 104715 total, starting on record 6746, ending on 6750