CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12584  CVE-2005-1378  Candidate  SQL injection vulnerability in posting_notes.php in the notes module for phpBB allows remote attackers to execute arbitrary SQL commands via the p parameter, which is used in the $post_id variable, and other attack vectors.  Assigned (20050502)  None (candidate not yet proposed)    View
12585  CVE-2005-1379  Candidate  The LAM runtime environment package (lam-runtime-7.0.6-2mdk) on Mandrake Linux installs the mpi user without a password, which allows local users to gain privileges.  Assigned (20050502)  None (candidate not yet proposed)    View
12586  CVE-2005-1380  Candidate  Cross-site scripting (XSS) vulnerability in BEA Admin Console 8.1 allows remote attackers to execute arbitrary web script or HTML via the server parameter to a JndiFramesetAction action.  Assigned (20050502)  None (candidate not yet proposed)    View
12587  CVE-2005-1381  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web script or HTML via the (1) cache_dump_file or (2) PartialPageErrorPage parameter.  Assigned (20050502)  None (candidate not yet proposed)    View
12588  CVE-2005-1382  Candidate  The webcacheadmin module in Oracle Webcache 9i allows remote attackers to corrupt arbitrary files via a full pathname in the cache_dump_file parameter.  Assigned (20050502)  None (candidate not yet proposed)    View

Page 1455 of 20943, showing 5 records out of 104715 total, starting on record 7271, ending on 7275

Actions