CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12644 | CVE-2005-1438 | Candidate | PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir parameter. | Assigned (20050503) | None (candidate not yet proposed) | View | |
12645 | CVE-2005-1439 | Candidate | Directory traversal vulnerability in attachments.php in osTicket allows remote attackers to read arbitrary files via .. sequences in the file parameter. | Assigned (20050503) | None (candidate not yet proposed) | View | |
12646 | CVE-2005-1440 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) various parameters to basket.php, (2) the nickname, email, topic, and message fields in forum.php, as demonstrated using forum_new_thread.php and forum_thread.php, (3) the page parameter to page.php, (4) category_id and item_id parameters to reviews.php, (5) the category_id parameter to product_details.php, (6) the category_id or search_string parameters to products.php, or (7) the rp or page parameters to news_view.php. | Assigned (20050503) | None (candidate not yet proposed) | View | |
12647 | CVE-2005-1441 | Candidate | Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC). | Assigned (20050503) | None (candidate not yet proposed) | View | |
12648 | CVE-2005-1442 | Candidate | Buffer overflow in the Lotus Notes client for Domino 6.5 before 6.5.4 and 6.0 before 6.0.5 allows local users to cause a denial of service (client crash) and possibly execute arbitrary code via the NOTES.INI file. | Assigned (20050503) | None (candidate not yet proposed) | View |
Page 1467 of 20943, showing 5 records out of 104715 total, starting on record 7331, ending on 7335