CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13264  CVE-2005-2058  Candidate  Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.php, (3) mailthread.php, or (4) notifymod.php, (5) month or (6) year parameter to calendar.php, (7) message parameter to viewmessage.php, (8) main parameter to addfav.php, or (9) posted parameter to grabnext.php.  Assigned (20050629)  None (candidate not yet proposed)    View
6353  CVE-2002-1971  Candidate  The ping utility in networking_utils.php in Sourcecraft Networking_Utils 1.0 allows remote attackers to read arbitrary files via shell metacharacters in the Domain name or IP address argument.  Assigned (20050629)  None (candidate not yet proposed)    View
13265  CVE-2005-2059  Candidate  Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to modify settings as another user via a link or IMG tag.  Assigned (20050629)  None (candidate not yet proposed)    View
6354  CVE-2002-1972  Candidate  Unknown vulnerability in Parallel port powerSwitch (aka pp_powerSwitch) 0.1 does not properly enforce access controls, which allows local users to access arbitrary ports.  Assigned (20050629)  None (candidate not yet proposed)    View
13266  CVE-2005-2060  Candidate  Multiple HTTP Response Splitting vulnerabilities in (1) toggleshow.php, (2) togglecats.php, and (3) showprofile.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the Cat parameter.  Assigned (20050629)  None (candidate not yet proposed)    View

Page 1748 of 20943, showing 5 records out of 104715 total, starting on record 8736, ending on 8740

Actions