CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12318  CVE-2005-1112  Candidate  IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processed by the web server instead of the JSP engine.  Assigned (20050416)  None (candidate not yet proposed)    View
12319  CVE-2005-1113  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in PhpBB Plus 1.52 and earlier allow remote attackers to inject arbitrary web script or HTML via the bsid parameter to (1) groupcp.php, (2) index.php, (3) portal.php, (4) viewforum.php, or (5) viewtopic.php, (6) the c parameter to index.php, or (7) the article parameter to portal.php.  Assigned (20050416)  None (candidate not yet proposed)    View
12320  CVE-2005-1114  Candidate  Multiple SQL injection vulnerabilities in album_search.php in Photo Album 2.0.53 for phpBB allow remote attackers to execute arbitrary SQL commands via the (1) mode or (2) search parameters.  Assigned (20050416)  None (candidate not yet proposed)    View
12321  CVE-2005-1115  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Photo Album 2.0.53 module for phpBB allow remote attackers to inject arbitrary web script or HTML via the bsid parameter to (1) album_cat.php or (2) album_comment.php.  Assigned (20050416)  None (candidate not yet proposed)    View
12322  CVE-2005-1116  Candidate  Cross-site scripting (XSS) vulnerability in the Calendar module for phpBB allow remote attackers to inject arbitrary web script or HTML via the start parameter to calendar_scheduler.php.  Assigned (20050416)  None (candidate not yet proposed)    View

Page 1388 of 20943, showing 5 records out of 104715 total, starting on record 6936, ending on 6940

Actions