CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12233  CVE-2005-1027  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x through 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter in the Your_Account module, (2) avatarcategory parameter in the Your_Account module, or (3) lid parameter in the Downloads module.  Assigned (20050410)  None (candidate not yet proposed)    View
12234  CVE-2005-1028  Candidate  PHP-Nuke 6.x through 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) index.php with the forum_admin parameter set, (2) the Surveys module, or (3) the Your_Account module, which reveals the path in a PHP error message.  Assigned (20050410)  None (candidate not yet proposed)    View
12235  CVE-2005-1029  Candidate  Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) SortDir, or (3) Sortby parameter to default.asp, (4) itemID parameter to ItemInfo.asp, or (5) Email field to sendpassword.asp.  Assigned (20050410)  None (candidate not yet proposed)    View
12236  CVE-2005-1030  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary web script or HTML via the (1) ReturnURL, (2) password, (3) username parameter, (4) ReturnURL parameter to account.asp, (5) Table, (6) Title parameter to sendpassword.asp, or (7) itemid to watchthisitem.asp.  Assigned (20050410)  None (candidate not yet proposed)    View
12237  CVE-2005-1031  Candidate  RUNCMS 1.1A, and possibly other products based on e-Xoops (exoops), when "Allow custom avatar upload" is enabled, does not properly verify uploaded files, which allows remote attackers to upload arbitrary files.  Assigned (20050410)  None (candidate not yet proposed)    View

Page 1371 of 20943, showing 5 records out of 104715 total, starting on record 6851, ending on 6855

Actions