CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13160  CVE-2005-1954  Candidate  singapore 0.9.11 allows remote attackers to obtain sensitive information via a direct request to (1) admin.class.php, (2) any .tpl.php file in templates/admin_default/, or (3) any .tpl.php file in templates/default/, which reveal the path in an error message.  Assigned (20050614)  None (candidate not yet proposed)    View
13161  CVE-2005-1955  Candidate  Cross-site scripting (XSS) vulnerability in index.php in singapore 0.9.11 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter.  Assigned (20050614)  None (candidate not yet proposed)    View
13162  CVE-2005-1956  Candidate  File Upload Manager allows remote attackers to upload arbitrary files by modifying the test variable to contain a value of "~~~~~~" (six tildes), which bypasses the file extension checks.  Assigned (20050614)  None (candidate not yet proposed)    View
13163  CVE-2005-1957  Candidate  mtnpeak.net File Upload Manager does not properly check user authentication for certain actions, which allows remote attackers to provide a modified base64-encoded file parameter and (1) read arbitrary files via the "view" action or (2) delete arbitrary files via the del action.  Assigned (20050614)  None (candidate not yet proposed)    View
13164  CVE-2005-1958  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-1855. Reason: This candidate is a duplicate of CVE-2005-1855. Notes: All CVE users should reference CVE-2005-1855 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20050614)  None (candidate not yet proposed)    View

Page 1661 of 20943, showing 5 records out of 104715 total, starting on record 8301, ending on 8305

Actions