CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12228  CVE-2005-1022  Candidate  ColdFusion 6.1 Updater 1 places Java .class files under the web root in the /WEB-INF/cfclasses directory, which allows remote attackers to obtain sensitive information.  Assigned (20050410)  None (candidate not yet proposed)    View
12229  CVE-2005-1023  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x to 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) min parameter to the Search module, (2) the categories parameter to the FAQ module, or (3) the ltr parameter to the Encyclopedia module. NOTE: the bid parameter issue in banners.php is already an item in CVE-2005-1000.  Assigned (20050410)  None (candidate not yet proposed)    View
12230  CVE-2005-1024  Candidate  modules.php in PHP-Nuke 6.x to 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) my_headlines, (2) userinfo, or (3) search, which reveals the path in a PHP error message.  Assigned (20050410)  None (candidate not yet proposed)    View
12231  CVE-2005-1025  Candidate  The FTP server in AS/400 4.3, when running in IFS mode, allows remote attackers to obtain sensitive information via a symlink attack using RCMD and the ADDLNK utility, as demonstrated using the QSYS.LIB library.  Assigned (20050410)  None (candidate not yet proposed)    View
12232  CVE-2005-1026  Candidate  Multiple SQL injection vulnerabilities in SnailSource phpBB 2.0.x mods allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to dlman.php in DLMan Pro or (2) id parameter to links.php in Linkz Pro (aka LinksLinks Pro).  Assigned (20050410)  None (candidate not yet proposed)    View

Page 1370 of 20943, showing 5 records out of 104715 total, starting on record 6846, ending on 6850

Actions