CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13317 | CVE-2005-2111 | Candidate | login.cgi in Community Link Pro Web Editor allows remote attackers to execute arbitrary commands via the file parameter. | Assigned (20050701) | None (candidate not yet proposed) | View | |
13318 | CVE-2005-2112 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) order parameter to edit.php or (2) cid parameter to comment_edit.php. | Assigned (20050701) | None (candidate not yet proposed) | View | |
13319 | CVE-2005-2113 | Candidate | SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via crafted values in an XML file, as demonstrated using the blogger.getPost method. | Assigned (20050701) | None (candidate not yet proposed) | View | |
13320 | CVE-2005-2114 | Candidate | Mozilla 1.7.8, Firefox 1.0.4, Camino 0.8.4, Netscape 8.0.2, and K-Meleon 0.9, and possibly other products that use the Gecko engine, allow remote attackers to cause a denial of service (application crash) via JavaScript that repeatedly calls an empty function. | Assigned (20050701) | None (candidate not yet proposed) | View | |
13321 | CVE-2005-2115 | Candidate | Soldier of Fortune II 1.02x and 1.03 allows remote attackers to cause a denial of service (server crash) via a large ID value in the ignore command, which is used as an array index and causes an out-of-bounds operation. | Assigned (20050701) | None (candidate not yet proposed) | View |
Page 1763 of 20943, showing 5 records out of 104715 total, starting on record 8811, ending on 8815