CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12405  CVE-2005-1199  Candidate  SQL injection vulnerability in printthread.php in UBB.Threads allows remote attackers to execute arbitrary SQL commands via the main parameter.  Assigned (20050421)  None (candidate not yet proposed)    View
12406  CVE-2005-1200  Candidate  PHP remote file inclusion vulnerability in main_index.php in AZ Bulletin Board (AZbb) 1.0.07a through 1.0.07c allows remote attackers to execute arbitrary PHP code by modifying the (1) dir_src or (2) abs_layer parameter to reference a URL on a remote web server that contains the code.  Assigned (20050421)  None (candidate not yet proposed)    View
12407  CVE-2005-1201  Candidate  Multiple directory traversal vulnerabilities in AZ Bulletin board (AZbb) before 1.0.08 allow (1) remote authenticated users with administrative privileges to delete arbitrary files via a .. (dot dot) in the URL to admin_avatar.php or admin_attachment.php or (2) remote attackers to enumerate files via a .. (dot dot) in the attachment parameter to attachment.php, which displays a different message when a file exists or does not exist.  Assigned (20050421)  None (candidate not yet proposed)    View
12408  CVE-2005-1202  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in eGroupware before 1.0.0.007 allow remote attackers to inject arbitrary web script or HTML via the (1) ab_id, (2) page, (3) type, or (4) lang parameter to index.php or (5) category_id parameter.  Assigned (20050421)  None (candidate not yet proposed)    View
12409  CVE-2005-1203  Candidate  Multiple SQL injection vulnerabilities in index.php in eGroupware before 1.0.0.007 allow remote attackers to execute arbitrary SQL commands via the (1) filter or (2) cats_app parameter.  Assigned (20050421)  None (candidate not yet proposed)    View

Page 1408 of 20943, showing 5 records out of 104715 total, starting on record 7036, ending on 7040

Actions