CVE List

Id CVE No. Status Description Phase Votes Comments Actions
15284  CVE-2005-4080  Candidate  Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via UTF16 encoded attachments and strings that will be executed when viewed using Internet Explorer, which ignores the characters.  Assigned (20051208)  None (candidate not yet proposed)    View
15285  CVE-2005-4081  Candidate  Multiple SQL injection vulnerabilities in Alisveristr E-commerce allow remote attackers to bypass authentication and possibly execute arbitrary SQL commands via the username and password parameters in (1) the user login and (2) administrator login pages.  Assigned (20051208)  None (candidate not yet proposed)    View
15286  CVE-2005-4082  Candidate  The dhcp.client program for QNX 4.25 vmware is setuid, possibly by default, which allows local users to modify the NIC configuration and conduct other attacks.  Assigned (20051208)  None (candidate not yet proposed)    View
15287  CVE-2005-4083  Candidate  Directory traversal vulnerability in xs_edit.php in the eXtreme Styles phpBB module 2.2.1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the edit parameter.  Assigned (20051208)  None (candidate not yet proposed)    View
15288  CVE-2005-4084  Candidate  xs_edit.php in the phpBB eXtreme Styles module 2.2.1 and earlier allows remote attackers to obtain the installation path of the application via an invalid viewbackup parameter.  Assigned (20051208)  None (candidate not yet proposed)    View

Page 18604 of 20943, showing 5 records out of 104715 total, starting on record 93016, ending on 93020

Actions