CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13150 | CVE-2005-1944 | Candidate | xmysqladmin 1.0 and earlier allows local users to delete arbitrary files via a symlink attack on a database backup file in /tmp. | Assigned (20050614) | None (candidate not yet proposed) | View | |
13151 | CVE-2005-1945 | Candidate | Cross-site scripting (XSS) vulnerability in the convert_highlite_words function in Invision Blog before 1.1.2 Final allows remote attackers to inject arbitrary web script or HTML via double hex encoded highlight data. | Assigned (20050614) | None (candidate not yet proposed) | View | |
13152 | CVE-2005-1946 | Candidate | Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to an editentry, replyentry, or editcomment action, or (2) the mid parameter to an aboutme action. | Assigned (20050614) | None (candidate not yet proposed) | View | |
13153 | CVE-2005-1947 | Candidate | Cross-site request forgery (CSRF) vulnerability in Invision Gallery before 1.3.1 allows remote attackers to delete albums and images as another user via a link or IMG tag to the (1) albums or (2) delimg actions. | Assigned (20050614) | None (candidate not yet proposed) | View | |
13154 | CVE-2005-1948 | Candidate | Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo. | Assigned (20050614) | None (candidate not yet proposed) | View |
Page 1659 of 20943, showing 5 records out of 104715 total, starting on record 8291, ending on 8295