CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13317  CVE-2005-2111  Candidate  login.cgi in Community Link Pro Web Editor allows remote attackers to execute arbitrary commands via the file parameter.  Assigned (20050701)  None (candidate not yet proposed)    View
13318  CVE-2005-2112  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) order parameter to edit.php or (2) cid parameter to comment_edit.php.  Assigned (20050701)  None (candidate not yet proposed)    View
13319  CVE-2005-2113  Candidate  SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via crafted values in an XML file, as demonstrated using the blogger.getPost method.  Assigned (20050701)  None (candidate not yet proposed)    View
13320  CVE-2005-2114  Candidate  Mozilla 1.7.8, Firefox 1.0.4, Camino 0.8.4, Netscape 8.0.2, and K-Meleon 0.9, and possibly other products that use the Gecko engine, allow remote attackers to cause a denial of service (application crash) via JavaScript that repeatedly calls an empty function.  Assigned (20050701)  None (candidate not yet proposed)    View
13321  CVE-2005-2115  Candidate  Soldier of Fortune II 1.02x and 1.03 allows remote attackers to cause a denial of service (server crash) via a large ID value in the ignore command, which is used as an array index and causes an out-of-bounds operation.  Assigned (20050701)  None (candidate not yet proposed)    View

Page 1763 of 20943, showing 5 records out of 104715 total, starting on record 8811, ending on 8815

Actions