CVE List

Id CVE No. Status Description Phase Votes Comments Actions
15160  CVE-2005-3956  Candidate  Multiple SQL injection vulnerabilities in index.php in DMANews 0.904 and 0.910 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a comments action and the (2) sortorder and (3) display_num parameters in a news_list action.  Assigned (20051201)  None (candidate not yet proposed)    View
15161  CVE-2005-3957  Candidate  Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors.  Assigned (20051201)  None (candidate not yet proposed)    View
15162  CVE-2005-3958  Candidate  SQL injection vulnerability in index.php in Entergal MX 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) idcat parameter in a showcat action and (2) the action parameter.  Assigned (20051201)  None (candidate not yet proposed)    View
15163  CVE-2005-3959  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in FreeWebStat 1.0 rev37 allow remote attackers to inject arbitrary web script or HTML via the (1) site, (2) jsref, (3) jsres, and (4) jscolor parameters to pixel.php, which are not sanitized before being included in the logdb.html file, and (5) the search key to stat.php.  Assigned (20051201)  None (candidate not yet proposed)    View
15164  CVE-2005-3960  Candidate  Kadu 0.4.2 and 0.5.0pre allows remote attackers to cause a denial of service (crash or generated traffic) via a malformed message, possibly with incomplete information.  Assigned (20051201)  None (candidate not yet proposed)    View

Page 18642 of 20943, showing 5 records out of 104715 total, starting on record 93206, ending on 93210

Actions