CVE List

Id CVE No. Status Description Phase Votes Comments Actions
15155  CVE-2005-3951  Candidate  SQL injection vulnerability in survey.php in PHP Labs Survey Wizard allows remote attackers to execute arbitrary SQL commands via the sid parameter.  Assigned (20051201)  None (candidate not yet proposed)    View
15156  CVE-2005-3952  Candidate  SQL injection vulnerability in PHP Labs Top Auction allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) type parameters to viewcat.php, or (3) certain search parameters. NOTE: later a disclosure reported the affected version as 1.0.  Assigned (20051201)  None (candidate not yet proposed)    View
15157  CVE-2005-3953  Candidate  SQL injection vulnerability in Bedeng PSP 1.1 allows remote attackers to execute arbitrary SQL commands via the cwhere parameter to (1) index.php and (2) download.php, or (3) ckode parameter to baca.php.  Assigned (20051201)  None (candidate not yet proposed)    View
15158  CVE-2005-3954  Candidate  Cross-site scripting (XSS) vulnerability in blogBuddies 0.3 allows remote attackers to inject arbitrary web script or HTML via the u parameter to index.php.  Assigned (20051201)  None (candidate not yet proposed)    View
15159  CVE-2005-3955  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1, as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2, and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) magpie_debug.php and (2) rss_url parameter to (b) magpie_slashbox.php and (c) simple_smarty.php.  Assigned (20051201)  None (candidate not yet proposed)    View

Page 18641 of 20943, showing 5 records out of 104715 total, starting on record 93201, ending on 93205

Actions