CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12318 | CVE-2005-1112 | Candidate | IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processed by the web server instead of the JSP engine. | Assigned (20050416) | None (candidate not yet proposed) | View | |
12319 | CVE-2005-1113 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in PhpBB Plus 1.52 and earlier allow remote attackers to inject arbitrary web script or HTML via the bsid parameter to (1) groupcp.php, (2) index.php, (3) portal.php, (4) viewforum.php, or (5) viewtopic.php, (6) the c parameter to index.php, or (7) the article parameter to portal.php. | Assigned (20050416) | None (candidate not yet proposed) | View | |
12320 | CVE-2005-1114 | Candidate | Multiple SQL injection vulnerabilities in album_search.php in Photo Album 2.0.53 for phpBB allow remote attackers to execute arbitrary SQL commands via the (1) mode or (2) search parameters. | Assigned (20050416) | None (candidate not yet proposed) | View | |
12321 | CVE-2005-1115 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Photo Album 2.0.53 module for phpBB allow remote attackers to inject arbitrary web script or HTML via the bsid parameter to (1) album_cat.php or (2) album_comment.php. | Assigned (20050416) | None (candidate not yet proposed) | View | |
12322 | CVE-2005-1116 | Candidate | Cross-site scripting (XSS) vulnerability in the Calendar module for phpBB allow remote attackers to inject arbitrary web script or HTML via the start parameter to calendar_scheduler.php. | Assigned (20050416) | None (candidate not yet proposed) | View |
Page 1388 of 20943, showing 5 records out of 104715 total, starting on record 6936, ending on 6940