CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13462  CVE-2005-2256  Candidate  Encoded directory traversal vulnerability in phpPgAdmin 3.1 to 3.5.3 allows remote attackers to access arbitrary files via "%2e%2e%2f" (encoded dot dot) sequences in the formLanguage parameter.  Assigned (20050713)  None (candidate not yet proposed)    View
13463  CVE-2005-2257  Candidate  The saveProfile function in PhpSlash 0.8.0 allows remote attackers to modify arbitrary profiles and gain privileges by modifying the author_id parameter.  Assigned (20050713)  None (candidate not yet proposed)    View
13464  CVE-2005-2258  Candidate  PHP remote file inclusion vulnerability in photolist.inc.php in Squito Gallery 1.33 allows remote attackers to execute arbitrary code via the photoroot parameter.  Assigned (20050713)  None (candidate not yet proposed)    View
13465  CVE-2005-2259  Candidate  The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute arbitrary code via shell metacharacters in the DISPCLOSED parameter.  Assigned (20050713)  None (candidate not yet proposed)    View
13466  CVE-2005-2260  Candidate  The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-generated events and untrusted synthetic events, which makes it easier for remote attackers to perform dangerous actions that normally could only be performed manually by the user.  Assigned (20050713)  None (candidate not yet proposed)    View

Page 1806 of 20943, showing 5 records out of 104715 total, starting on record 9026, ending on 9030

Actions