CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
14949 | CVE-2005-3745 | Candidate | Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message. | Assigned (20051122) | None (candidate not yet proposed) | View | |
14950 | CVE-2005-3746 | Candidate | SQL injection vulnerability in thread.php in APBoard allows remote attackers to execute arbitrary SQL commands via the start parameter. | Assigned (20051122) | None (candidate not yet proposed) | View | |
14951 | CVE-2005-3747 | Candidate | Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash ("%5C") characters. NOTE: this might be the same issue as CVE-2006-2758. | Assigned (20051122) | None (candidate not yet proposed) | View | |
14952 | CVE-2005-3748 | Candidate | SQL injection vulnerability in the Search module in Tru-Zone Nuke ET 3.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the query parameter. | Assigned (20051122) | None (candidate not yet proposed) | View | |
14953 | CVE-2005-3749 | Candidate | Unspecified "absolute path vulnerabilities" in the diagela command (diagela.sh) in IBM AIX 5.2 and 5.3 have unknown impact and attack vectors. | Assigned (20051122) | None (candidate not yet proposed) | View |
Page 18686 of 20943, showing 5 records out of 104715 total, starting on record 93426, ending on 93430