CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
15253 | CVE-2005-4049 | Candidate | Multiple SQL injection vulnerabilities in Blog System 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the cat parameter in index.php and (2) the note parameter in blog.php. | Assigned (20051207) | None (candidate not yet proposed) | View | |
15254 | CVE-2005-4050 | Candidate | Buffer overflow in multiple Multi-Tech Systems MultiVOIP devices with firmware before x.08 allows remote attackers to execute arbitrary code via a long INVITE field in a Session Initiation Protocol (SIP) packet. | Assigned (20051207) | None (candidate not yet proposed) | View | |
15255 | CVE-2005-4051 | Candidate | e107 0.6174 allows remote attackers to vote multiple times for a download via repeated requests to rate.php. | Assigned (20051207) | None (candidate not yet proposed) | View | |
15256 | CVE-2005-4052 | Candidate | e107 0.6174 allows remote attackers to redirect users to other web sites via the download parameter in rate.php, which is used after a user submits a file download rating. NOTE: in the default installation, the e_BASE variable restricts the redirection to the same web site. | Assigned (20051207) | None (candidate not yet proposed) | View | |
15257 | CVE-2005-4053 | Candidate | Cross-site scripting (XSS) vulnerability in coWiki 0.3.4 allows remote attackers to inject arbitrary web script or HTML via the q parameter, as demonstrated using 26.html. | Assigned (20051207) | None (candidate not yet proposed) | View |
Page 18608 of 20943, showing 5 records out of 104715 total, starting on record 93036, ending on 93040