CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11500  CVE-2005-0294  Candidate  minis.php in Minis 0.2.1 allows remote attackers to cause a denial of service (infinite loop) via an HTTP request for a file that the web server does not have permission to read, as demonstrated using the month parameter.  Assigned (20050210)  None (candidate not yet proposed)    View
11499  CVE-2005-0293  Candidate  Directory traversal vulnerability in minis.php in Minis 0.2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the month parameter.  Assigned (20050210)  None (candidate not yet proposed)    View
11498  CVE-2005-0292  Candidate  Multiple SQL injection vulnerabilities in index.php in PHP Gift Registry (phpGiftReg) 1.4.0, and possibly other versions before 1.5.0b1, allow remote attackers to execute arbitrary SQL commands via the (1) messageid, (2) shopper, (3) shopfor, or (4) itemid parameters.  Assigned (20050210)  None (candidate not yet proposed)    View
11497  CVE-2005-0291  Candidate  Cross-site scripting (XSS) vulnerability in the log viewer in NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via a blocked URL phrase.  Assigned (20050210)  None (candidate not yet proposed)    View
11496  CVE-2005-0290  Candidate  NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to bypass the filters using hex encoded URLs, as demonstrated using a hex encoded file extension.  Assigned (20050210)  None (candidate not yet proposed)    View

Page 18644 of 20943, showing 5 records out of 104715 total, starting on record 93216, ending on 93220

Actions