CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
15228 | CVE-2005-4024 | Candidate | Cross-site scripting (XSS) vulnerability in Interspire FastFind 2004 and 2005 allows remote attackers to inject arbitrary web script or HTML via the query parameter. | Assigned (20051205) | None (candidate not yet proposed) | View | |
15229 | CVE-2005-4025 | Candidate | Help Desk Reloaded Free Help Desk does not remove or protect install.php once installation is complete, which allows remote attackers to gain privileges via a direct request to install.php, then navigating to accountsetup.php and creating a new user. | Assigned (20051205) | None (candidate not yet proposed) | View | |
15230 | CVE-2005-4026 | Candidate | search.php in Geeklog 1.4.x before 1.4.0rc1, and 1.3.x before 1.3.11sr3, allows remote attackers to obtain sensitive information via invalid (1) datestart and (2) dateend parameters, which leaks the web server path in an error message. | Assigned (20051205) | None (candidate not yet proposed) | View | |
15231 | CVE-2005-4027 | Candidate | SQL injection vulnerability in SimpleBBS 1.1 allows remote attackers to execute arbitrary SQL commands via unspecified search module parameters. | Assigned (20051205) | None (candidate not yet proposed) | View | |
15232 | CVE-2005-4028 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in aMember allow remote attackers to inject arbitrary web script or HTML via the (1) lamember_login parameter to sendpass.php and (2) login parameter to member.php. | Assigned (20051205) | None (candidate not yet proposed) | View |
Page 18618 of 20943, showing 5 records out of 104715 total, starting on record 93086, ending on 93090