CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
15155 | CVE-2005-3951 | Candidate | SQL injection vulnerability in survey.php in PHP Labs Survey Wizard allows remote attackers to execute arbitrary SQL commands via the sid parameter. | Assigned (20051201) | None (candidate not yet proposed) | View | |
15156 | CVE-2005-3952 | Candidate | SQL injection vulnerability in PHP Labs Top Auction allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) type parameters to viewcat.php, or (3) certain search parameters. NOTE: later a disclosure reported the affected version as 1.0. | Assigned (20051201) | None (candidate not yet proposed) | View | |
15157 | CVE-2005-3953 | Candidate | SQL injection vulnerability in Bedeng PSP 1.1 allows remote attackers to execute arbitrary SQL commands via the cwhere parameter to (1) index.php and (2) download.php, or (3) ckode parameter to baca.php. | Assigned (20051201) | None (candidate not yet proposed) | View | |
15158 | CVE-2005-3954 | Candidate | Cross-site scripting (XSS) vulnerability in blogBuddies 0.3 allows remote attackers to inject arbitrary web script or HTML via the u parameter to index.php. | Assigned (20051201) | None (candidate not yet proposed) | View | |
15159 | CVE-2005-3955 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1, as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2, and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) magpie_debug.php and (2) rss_url parameter to (b) magpie_slashbox.php and (c) simple_smarty.php. | Assigned (20051201) | None (candidate not yet proposed) | View |
Page 18641 of 20943, showing 5 records out of 104715 total, starting on record 93201, ending on 93205