CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10687 | CVE-2004-2261 | Candidate | Cross-site scripting (XSS) vulnerability in e107 allows remote attackers to inject arbitrary script or HTML via the "login name/author" field in the (1) news submit or (2) article submit functions. | Assigned (20050719) | None (candidate not yet proposed) | View | |
13503 | CVE-2005-2297 | Candidate | Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a large javascript parameter. | Assigned (20050719) | None (candidate not yet proposed) | View | |
10688 | CVE-2004-2262 | Candidate | ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php. | Assigned (20050719) | None (candidate not yet proposed) | View | |
13504 | CVE-2005-2298 | Candidate | BitDefender Engine 1.6.1 and earlier does not properly scan all attachments, which allows remote attackers to bypass virus scanning via begin and end commands in the body of the e-mail, which BitDefender treats as a uuencoded attachment and stops scanning afterwards. | Assigned (20050719) | None (candidate not yet proposed) | View | |
10689 | CVE-2004-2263 | Candidate | SQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to modify SQL statements via the vc2 cookie. | Assigned (20050719) | None (candidate not yet proposed) | View |
Page 1859 of 20943, showing 5 records out of 104715 total, starting on record 9291, ending on 9295