CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13215  CVE-2005-2009  Candidate  Multiple SQL injection vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) ci, (2) d, or (3) m parameter to index.asp, or the (4) bi parameter to blog_comment.asp.  Assigned (20050620)  None (candidate not yet proposed)    View
13216  CVE-2005-2010  Candidate  Cross-site scripting (XSS) vulnerability in trackback.asp in Ublog Reload 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the btitle parameter.  Assigned (20050620)  None (candidate not yet proposed)    View
13217  CVE-2005-2011  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in paFAQ 1.0 Beta 4 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the id parameter in a Question action.  Assigned (20050620)  None (candidate not yet proposed)    View
13218  CVE-2005-2012  Candidate  Multiple SQL injection vulnerabilities in login in paFAQ 1.0 Beta 4 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) id parameters.  Assigned (20050620)  None (candidate not yet proposed)    View
13219  CVE-2005-2013  Candidate  paFAQ 1.0 Beta 4 allows remote attackers to obtain sensitive information via a direct request to admin/backup.php, which contains a backup of the database including usernames and passwords.  Assigned (20050620)  None (candidate not yet proposed)    View

Page 1672 of 20943, showing 5 records out of 104715 total, starting on record 8356, ending on 8360

Actions