CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
15211 | CVE-2005-4007 | Candidate | Multiple unspecified vulnerabilities in SAPID CMS before 1.2.3.03, related to newly registered users and possibly authorization checks, have unknown impact and attack vectors involving (1) mvc/controller/user_request_analysis.inc.php and (2) usr/xml/ddc/authorization.xml. | Assigned (20051204) | None (candidate not yet proposed) | View | |
8112 | CVE-2003-1288 | Candidate | Multiple race conditions in Linux-VServer 1.22 with Linux kernel 2.4.23 and SMP allow local users to cause a denial of service (kernel oops) via unknown attack vectors related to the (1) s_info and (2) ip_info data structures and the (a) forget_original_parent, (b) goodness, (c) schedule, (d) update_process_times, and (e) vc_new_s_context functions. | Assigned (20051204) | None (candidate not yet proposed) | View | |
15170 | CVE-2005-3966 | Candidate | Cross-site scripting (XSS) vulnerability in search.jsp in Java Search Engine (JSE) 0.9.34 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | Assigned (20051203) | None (candidate not yet proposed) | View | |
15171 | CVE-2005-3967 | Candidate | Cross-site scripting (XSS) vulnerability in the dosearchsite.action module in Atlassian Confluence 2.0.1 Build 321 allows remote attackers to inject arbitrary web script or HTML via the searchQuery.queryString search module parameter. | Assigned (20051203) | None (candidate not yet proposed) | View | |
15172 | CVE-2005-3968 | Candidate | SQL injection vulnerability in auth.inc.php in PHPX 3.5.9 and earlier allows remote attackers to execute arbitrary SQL commands, bypass authentication, and upload arbitrary PHP code via the username parameter. | Assigned (20051203) | None (candidate not yet proposed) | View |
Page 18633 of 20943, showing 5 records out of 104715 total, starting on record 93161, ending on 93165