CVE List

Id CVE No. Status Description Phase Votes Comments Actions
15124  CVE-2005-3920  Candidate  SQL injection vulnerability in Babe Logger 2 allows remote attackers to execute arbitrary SQL commands via the (1) gal parameter to index.php or (2) id parameter to comments.php.  Assigned (20051130)  None (candidate not yet proposed)    View
15125  CVE-2005-3921  Candidate  Cross-site scripting (XSS) vulnerability in Cisco IOS Web Server for IOS 12.0(2a) allows remote attackers to inject arbitrary web script or HTML by (1) packets containing HTML that an administrator views via an HTTP interface to the contents of memory buffers, as demonstrated by the URI /level/15/exec/-/buffers/assigned/dump; or (2) sending the router Cisco Discovery Protocol (CDP) packets with HTML payload that an administrator views via the CDP status pages. NOTE: these vectors were originally reported as being associated with the dump and packet options in /level/15/exec/-/show/buffers.  Assigned (20051130)  None (candidate not yet proposed)    View
15126  CVE-2005-3922  Candidate  Heap-based buffer overflow in pskcmp.dll in Panda Software Antivirus library allows remote attackers to execute arbitrary code via a crafted ZOO archive.  Assigned (20051130)  None (candidate not yet proposed)    View
15127  CVE-2005-3923  Candidate  NetObjects Fusion 9 (NOF9) allows remote attackers to obtain sensitive information, including passwords, by downloading the _versioning_repository_/rollbacklog.xml file, then using it to download and modify the associated ZIP file to edit and republish the site.  Assigned (20051130)  None (candidate not yet proposed)    View
15128  CVE-2005-3924  Candidate  SQL injection vulnerability in themes/kategorie/index.php in Randshop allows remote attackers to execute arbitrary SQL commands via the (1) kategorieid and (2) katid parameters.  Assigned (20051130)  None (candidate not yet proposed)    View

Page 18649 of 20943, showing 5 records out of 104715 total, starting on record 93241, ending on 93245

Actions