CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12644  CVE-2005-1438  Candidate  PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir parameter.  Assigned (20050503)  None (candidate not yet proposed)    View
12645  CVE-2005-1439  Candidate  Directory traversal vulnerability in attachments.php in osTicket allows remote attackers to read arbitrary files via .. sequences in the file parameter.  Assigned (20050503)  None (candidate not yet proposed)    View
12646  CVE-2005-1440  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) various parameters to basket.php, (2) the nickname, email, topic, and message fields in forum.php, as demonstrated using forum_new_thread.php and forum_thread.php, (3) the page parameter to page.php, (4) category_id and item_id parameters to reviews.php, (5) the category_id parameter to product_details.php, (6) the category_id or search_string parameters to products.php, or (7) the rp or page parameters to news_view.php.  Assigned (20050503)  None (candidate not yet proposed)    View
12647  CVE-2005-1441  Candidate  Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC).  Assigned (20050503)  None (candidate not yet proposed)    View
12648  CVE-2005-1442  Candidate  Buffer overflow in the Lotus Notes client for Domino 6.5 before 6.5.4 and 6.0 before 6.0.5 allows local users to cause a denial of service (client crash) and possibly execute arbitrary code via the NOTES.INI file.  Assigned (20050503)  None (candidate not yet proposed)    View

Page 1467 of 20943, showing 5 records out of 104715 total, starting on record 7331, ending on 7335

Actions