CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13312  CVE-2005-2106  Candidate  Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.  Assigned (20050701)  None (candidate not yet proposed)    View
13313  CVE-2005-2107  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p or (2) comment parameter.  Assigned (20050701)  None (candidate not yet proposed)    View
13314  CVE-2005-2108  Candidate  SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file.  Assigned (20050701)  None (candidate not yet proposed)    View
13315  CVE-2005-2109  Candidate  wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use.  Assigned (20050701)  None (candidate not yet proposed)    View
13316  CVE-2005-2110  Candidate  WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or (4) wp-rss2.php, which reveal the path in an error message. NOTE: vector [1] was later reported to also affect WordPress 2.0.1.  Assigned (20050701)  None (candidate not yet proposed)    View

Page 1762 of 20943, showing 5 records out of 104715 total, starting on record 8806, ending on 8810

Actions