CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11685 | CVE-2005-0479 | Candidate | Directory traversal vulnerability in ComGetLogFile.php3 for TrackerCam 5.12 and earlier allows remote attackers to read arbitrary files via ".." sequences and (1) "/" slash), (2) "" (backslash), or (3) hex-encoded characters in the fn parameter. | Assigned (20050219) | None (candidate not yet proposed) | View | |
11684 | CVE-2005-0478 | Candidate | Multiple buffer overflows in TrackerCam 5.12 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) an HTTP request with a long User-Agent header or (2) a long argument to an arbitrary PHP script. | Assigned (20050219) | None (candidate not yet proposed) | View | |
11683 | CVE-2005-0477 | Candidate | Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to inject arbitrary web script via (1) a signature file or (2) a message post containing an IMG tag within a COLOR tag whose style is set to background:url. | Assigned (20050219) | None (candidate not yet proposed) | View | |
11682 | CVE-2005-0476 | Candidate | Cross-site scripting (XSS) vulnerability in hpm_guestbook.cgi allows remote attackers to inject arbitrary web script or HTML by posting a message. | Assigned (20050219) | None (candidate not yet proposed) | View | |
11681 | CVE-2005-0475 | Candidate | SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQL code via the (1) offset, (2) limit, (3) order, or (4) orderby parameter to question.php, (5) offset parameter to answer.php, (6) search_item parameter to search.php, (7) cat_id, (8) cid, or (9) id parameter to comment.php. | Assigned (20050219) | None (candidate not yet proposed) | View |
Page 18607 of 20943, showing 5 records out of 104715 total, starting on record 93031, ending on 93035