CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12764 | CVE-2005-1558 | Candidate | The web module in Neteyes Nexusway allows remote attackers to bypass authentication and gain administrator privileges by setting the cyclone500_auth cookie. | Assigned (20050514) | None (candidate not yet proposed) | View | |
12765 | CVE-2005-1559 | Candidate | The web module in Neteyes Nexusway allows remote attackers to execute arbitrary commands via hex-encoded shell metacharacters in the ip parameter for (1) nslookup.cgi or (2) ping.cgi. | Assigned (20050514) | None (candidate not yet proposed) | View | |
12766 | CVE-2005-1560 | Candidate | The SSH module in Neteyes Nexusway allows remote attackers to execute arbitrary commands via shell metacharacters in arguments to certain commands, as demonstrated using ping and traceroute. | Assigned (20050514) | None (candidate not yet proposed) | View | |
12767 | CVE-2005-1561 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in post.asp in MaxWebPortal 1.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mod, (2) M, or (3) type parameter. | Assigned (20050514) | None (candidate not yet proposed) | View | |
12768 | CVE-2005-1562 | Candidate | Multiple SQL injection vulnerabilities in MaxWebPortal 1.3.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fpassword parameter to inc_functions.asp, (2) txtAddress, (3) message, or (4) subject parameter to post_info.asp, (5) andor parameter to search.asp, (6) verkey parameter to pop_profile.asp, or (7) Remove or (8) Delete parameter to pm_delete2.asp. | Assigned (20050514) | None (candidate not yet proposed) | View |
Page 1564 of 20943, showing 5 records out of 104715 total, starting on record 7816, ending on 7820