CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14993  CVE-2005-3789  Candidate  Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) form_lang parameter in login.php and (2) the imgdir parameter in random_image.php.  Assigned (20051124)  None (candidate not yet proposed)    View
14994  CVE-2005-3790  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in act_newsletter.php in phpwcms 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) i and (2) text parameters.  Assigned (20051124)  None (candidate not yet proposed)    View
14995  CVE-2005-3791  Candidate  HTTP response splitting vulnerability in phpAdsNew and phpPgAds 2.0.6 and earlier allows remote attackers to inject arbitrary HTML headers via adclick.php and possibly other unspecified vectors.  Assigned (20051124)  None (candidate not yet proposed)    View
14996  CVE-2005-3792  Candidate  Multiple SQL injection vulnerabilities in the Search module in PHP-Nuke 7.8, and possibly other versions before 7.9 with patch 3.1, allows remote attackers to execute arbitrary SQL commands, as demonstrated via the query parameter in a stories type.  Assigned (20051124)  None (candidate not yet proposed)    View
14997  CVE-2005-3793  Candidate  Multiple SQL injection vulnerabilities in AlstraSoft Affiliate Network Pro 7.2 allow remote attackers to bypass authentication and execute arbitrary SQL commands via the (1) username or (2) password to admin/admin_validate_login, or the (3) login, (4) password, and (5) flag parameters to login_validate.php.  Assigned (20051124)  None (candidate not yet proposed)    View

Page 18679 of 20943, showing 5 records out of 104715 total, starting on record 93391, ending on 93395

Actions