CVE List

Id CVE No. Status Description Phase Votes Comments Actions
15235  CVE-2005-4031  Candidate  Eval injection vulnerability in MediaWiki 1.5.x before 1.5.3 allows remote attackers to execute arbitrary PHP code via the "user language option," which is used as part of a dynamic class name that is processed using the eval function.  Assigned (20051206)  None (candidate not yet proposed)    View
15236  CVE-2005-4032  Candidate  Cross-site scripting (XSS) vulnerability in search.cgi in Easy Search System 1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter.  Assigned (20051206)  None (candidate not yet proposed)    View
15237  CVE-2005-4033  Candidate  Nodezilla 0.4.13-corno-fulgure does not properly protect the evl_data directory, which could allow them to be shared when they are not protected by PRIVATEDATADIR in nodezilla.ini, which allows remote attackers to obtain sensitive information.  Assigned (20051206)  None (candidate not yet proposed)    View
15238  CVE-2005-4034  Candidate  Multiple SQL injection vulnerabilities in Web4Future eDating Professional 5 allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) pg, and (3) sortb parameters to (a) index.php; (4) cid parameter to (b) gift.php and (c) fq.php; and (5) cat parameter to (d) articles.php.  Assigned (20051206)  None (candidate not yet proposed)    View
15239  CVE-2005-4035  Candidate  Multiple SQL injection vulnerabilities in Web4Future eCommerce Enterprise Edition 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) prod, and (2) brid parameters to (a) view.php; the (3) the bid parameter to (b) viewbrands.php; and the (4) grp and (5) cat parameters to index.php.  Assigned (20051206)  None (candidate not yet proposed)    View

Page 18612 of 20943, showing 5 records out of 104715 total, starting on record 93056, ending on 93060

Actions