CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10687  CVE-2004-2261  Candidate  Cross-site scripting (XSS) vulnerability in e107 allows remote attackers to inject arbitrary script or HTML via the "login name/author" field in the (1) news submit or (2) article submit functions.  Assigned (20050719)  None (candidate not yet proposed)    View
13503  CVE-2005-2297  Candidate  Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a large javascript parameter.  Assigned (20050719)  None (candidate not yet proposed)    View
10688  CVE-2004-2262  Candidate  ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php.  Assigned (20050719)  None (candidate not yet proposed)    View
13504  CVE-2005-2298  Candidate  BitDefender Engine 1.6.1 and earlier does not properly scan all attachments, which allows remote attackers to bypass virus scanning via begin and end commands in the body of the e-mail, which BitDefender treats as a uuencoded attachment and stops scanning afterwards.  Assigned (20050719)  None (candidate not yet proposed)    View
10689  CVE-2004-2263  Candidate  SQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to modify SQL statements via the vc2 cookie.  Assigned (20050719)  None (candidate not yet proposed)    View

Page 1859 of 20943, showing 5 records out of 104715 total, starting on record 9291, ending on 9295

Actions