CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13155  CVE-2005-1949  Candidate  The eping_validaddr function in functions.php for the ePing plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacters after a valid argument to the eping_host parameter.  Assigned (20050614)  None (candidate not yet proposed)    View
13156  CVE-2005-1950  Candidate  hints.pl in Webhints 1.03 allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.  Assigned (20050614)  None (candidate not yet proposed)    View
13157  CVE-2005-1951  Candidate  Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences in the (1) products_id or (2) pid parameter to index.php or (3) goto parameter to banner.php.  Assigned (20050614)  None (candidate not yet proposed)    View
13158  CVE-2005-1952  Candidate  Directory traversal vulnerability in Pico Server (pServ) 3.3 allows remote attackers to read arbitrary files and execute arbitrary commands via a /./ (slash dot slash) before each .. (dot dot) sequence in the URL, which results in an incorrect directory depth count.  Assigned (20050614)  None (candidate not yet proposed)    View
13159  CVE-2005-1953  Candidate  Heap-based buffer overflow in the CGI extension for Pico Server (pServ) 3.3 allows remote attackers to execute arbitrary code via a long HTTP request.  Assigned (20050614)  None (candidate not yet proposed)    View

Page 1660 of 20943, showing 5 records out of 104715 total, starting on record 8296, ending on 8300

Actions