CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11500 | CVE-2005-0294 | Candidate | minis.php in Minis 0.2.1 allows remote attackers to cause a denial of service (infinite loop) via an HTTP request for a file that the web server does not have permission to read, as demonstrated using the month parameter. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11499 | CVE-2005-0293 | Candidate | Directory traversal vulnerability in minis.php in Minis 0.2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the month parameter. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11498 | CVE-2005-0292 | Candidate | Multiple SQL injection vulnerabilities in index.php in PHP Gift Registry (phpGiftReg) 1.4.0, and possibly other versions before 1.5.0b1, allow remote attackers to execute arbitrary SQL commands via the (1) messageid, (2) shopper, (3) shopfor, or (4) itemid parameters. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11497 | CVE-2005-0291 | Candidate | Cross-site scripting (XSS) vulnerability in the log viewer in NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via a blocked URL phrase. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11496 | CVE-2005-0290 | Candidate | NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to bypass the filters using hex encoded URLs, as demonstrated using a hex encoded file extension. | Assigned (20050210) | None (candidate not yet proposed) | View |
Page 18644 of 20943, showing 5 records out of 104715 total, starting on record 93216, ending on 93220