CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12808  CVE-2005-1602  Candidate  SQL injection vulnerability in login.asp for Net56 Browser Based File Manager 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the password field.  Assigned (20050516)  None (candidate not yet proposed)    View
12809  CVE-2005-1603  Candidate  NiteEnterprises Remote File Manager 1.0 allows remote attackers to cause a denial of service (crash) via a crafted string to TCP port 7080.  Assigned (20050516)  None (candidate not yet proposed)    View
12810  CVE-2005-1604  Candidate  PHP Advanced Transfer Manager (phpATM) 1.21 allows remote attackers to upload arbitrary files via filenames containing multiple file extensions, as demonstrated using a filename ending in "php.ns", which allows execution of arbitrary PHP code.  Assigned (20050516)  None (candidate not yet proposed)    View
12811  CVE-2005-1605  Candidate  Cross-site scripting (XSS) vulnerability in the guestbook for SiteStudio 1.6 allows remote attackers to inject arbitrary web script or HTML via the name field to (1) psoft.guestbook.GuestBookServ in Standalone Site Studio or (2) E-Guest_sign.pl in Integrated Site Studio with H-Sphere.  Assigned (20050516)  None (candidate not yet proposed)    View
12812  CVE-2005-1606  Candidate  H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, which allows local users to gain privileges.  Assigned (20050516)  None (candidate not yet proposed)    View

Page 1572 of 20943, showing 5 records out of 104715 total, starting on record 7856, ending on 7860

Actions