CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
15274 | CVE-2005-4070 | Candidate | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-3665. Reason: This candidate is a reservation duplicate of CVE-2005-3665. Notes: All CVE users should reference CVE-2005-3665 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. | Assigned (20051208) | None (candidate not yet proposed) | View | |
15275 | CVE-2005-4071 | Candidate | Multiple SQL injection vulnerabilities in CFMagic Magic Forum Personal 2.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ForumID parameter in view_forum.cfm, and (2) ForumID, (3) Thread, and (4) ThreadID parameters in view_thread.cfm. | Assigned (20051208) | None (candidate not yet proposed) | View | |
15276 | CVE-2005-4072 | Candidate | Cross-site scripting (XSS) vulnerability in CFMagic Magic Forum Personal 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the Words parameter in search_forums.cfm, as used in the "Search For:" field. | Assigned (20051208) | None (candidate not yet proposed) | View | |
15277 | CVE-2005-4073 | Candidate | SQL injection vulnerability in view_archive.cfm in CFMagic Magic List Pro 2.5 allows remote attackers to execute arbitrary SQL commands via the ListID parameter. | Assigned (20051208) | None (candidate not yet proposed) | View | |
15278 | CVE-2005-4074 | Candidate | Directory traversal vulnerability in index.cfm in CF_Nuke 4.6 and earlier, when Sandbox Security is disabled, allows remote attackers to include arbitrary local .cfm files via a .. (dot dot) in the (1) sector or (2) page parameters. | Assigned (20051208) | None (candidate not yet proposed) | View |
Page 18602 of 20943, showing 5 records out of 104715 total, starting on record 93006, ending on 93010