CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
15160 | CVE-2005-3956 | Candidate | Multiple SQL injection vulnerabilities in index.php in DMANews 0.904 and 0.910 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a comments action and the (2) sortorder and (3) display_num parameters in a news_list action. | Assigned (20051201) | None (candidate not yet proposed) | View | |
15161 | CVE-2005-3957 | Candidate | Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors. | Assigned (20051201) | None (candidate not yet proposed) | View | |
15162 | CVE-2005-3958 | Candidate | SQL injection vulnerability in index.php in Entergal MX 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) idcat parameter in a showcat action and (2) the action parameter. | Assigned (20051201) | None (candidate not yet proposed) | View | |
15163 | CVE-2005-3959 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in FreeWebStat 1.0 rev37 allow remote attackers to inject arbitrary web script or HTML via the (1) site, (2) jsref, (3) jsres, and (4) jscolor parameters to pixel.php, which are not sanitized before being included in the logdb.html file, and (5) the search key to stat.php. | Assigned (20051201) | None (candidate not yet proposed) | View | |
15164 | CVE-2005-3960 | Candidate | Kadu 0.4.2 and 0.5.0pre allows remote attackers to cause a denial of service (crash or generated traffic) via a malformed message, possibly with incomplete information. | Assigned (20051201) | None (candidate not yet proposed) | View |
Page 18642 of 20943, showing 5 records out of 104715 total, starting on record 93206, ending on 93210