CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14949  CVE-2005-3745  Candidate  Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.  Assigned (20051122)  None (candidate not yet proposed)    View
14950  CVE-2005-3746  Candidate  SQL injection vulnerability in thread.php in APBoard allows remote attackers to execute arbitrary SQL commands via the start parameter.  Assigned (20051122)  None (candidate not yet proposed)    View
14951  CVE-2005-3747  Candidate  Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash ("%5C") characters. NOTE: this might be the same issue as CVE-2006-2758.  Assigned (20051122)  None (candidate not yet proposed)    View
14952  CVE-2005-3748  Candidate  SQL injection vulnerability in the Search module in Tru-Zone Nuke ET 3.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the query parameter.  Assigned (20051122)  None (candidate not yet proposed)    View
14953  CVE-2005-3749  Candidate  Unspecified "absolute path vulnerabilities" in the diagela command (diagela.sh) in IBM AIX 5.2 and 5.3 have unknown impact and attack vectors.  Assigned (20051122)  None (candidate not yet proposed)    View

Page 18686 of 20943, showing 5 records out of 104715 total, starting on record 93426, ending on 93430

Actions