CVE List

Id CVE No. Status Description Phase Votes Comments Actions
15253  CVE-2005-4049  Candidate  Multiple SQL injection vulnerabilities in Blog System 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the cat parameter in index.php and (2) the note parameter in blog.php.  Assigned (20051207)  None (candidate not yet proposed)    View
15254  CVE-2005-4050  Candidate  Buffer overflow in multiple Multi-Tech Systems MultiVOIP devices with firmware before x.08 allows remote attackers to execute arbitrary code via a long INVITE field in a Session Initiation Protocol (SIP) packet.  Assigned (20051207)  None (candidate not yet proposed)    View
15255  CVE-2005-4051  Candidate  e107 0.6174 allows remote attackers to vote multiple times for a download via repeated requests to rate.php.  Assigned (20051207)  None (candidate not yet proposed)    View
15256  CVE-2005-4052  Candidate  e107 0.6174 allows remote attackers to redirect users to other web sites via the download parameter in rate.php, which is used after a user submits a file download rating. NOTE: in the default installation, the e_BASE variable restricts the redirection to the same web site.  Assigned (20051207)  None (candidate not yet proposed)    View
15257  CVE-2005-4053  Candidate  Cross-site scripting (XSS) vulnerability in coWiki 0.3.4 allows remote attackers to inject arbitrary web script or HTML via the q parameter, as demonstrated using 26.html.  Assigned (20051207)  None (candidate not yet proposed)    View

Page 18608 of 20943, showing 5 records out of 104715 total, starting on record 93036, ending on 93040

Actions