CVE List

Id CVE No. Status Description Phase Votes Comments Actions
15129  CVE-2005-3925  Candidate  Multiple SQL injection vulnerabilities in Central Manchester CLC Helpdesk Issue Manager 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) detail[], (2) orderdir, and (3) orderby parameters to find.php, and the (4) id parameter to issue.php.  Assigned (20051130)  None (candidate not yet proposed)    View
15130  CVE-2005-3926  Candidate  Direct static code injection vulnerability in error.php in GuppY 4.5.9 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via the _SERVER[REMOTE_ADDR] parameter, which is injected into a .inc script that is later included by the main script.  Assigned (20051130)  None (candidate not yet proposed)    View
15131  CVE-2005-3927  Candidate  Multiple directory traversal vulnerabilities in GuppY 4.5.9 and earlier allow remote attackers to read and include arbitrary files via (1) the meskin parameter to admin/editorTypetool.php, or the lng parameter to the in admin/inc scripts (2) archbatch.php, (3) dbbatch.php, and (4) nwlmail.php.  Assigned (20051130)  None (candidate not yet proposed)    View
15132  CVE-2005-3928  Candidate  Buffer overflow in phgrafx in QNX 6.2.1 and 6.3.0 allows local users to execute arbitrary code via a long command line argument.  Assigned (20051130)  None (candidate not yet proposed)    View
15133  CVE-2005-3929  Candidate  Directory traversal vulnerability in the create function in xarMLSXML2PHPBackend.php in Xaraya 1.0 allows remote attackers to create directories and overwrite arbitrary files via ".." sequences in the module parameter to index.php.  Assigned (20051130)  None (candidate not yet proposed)    View

Page 18650 of 20943, showing 5 records out of 104715 total, starting on record 93246, ending on 93250

Actions