CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
14969 | CVE-2005-3765 | Candidate | Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows remote attackers to execute arbitrary code. | Assigned (20051122) | None (candidate not yet proposed) | View | |
14970 | CVE-2005-3766 | Candidate | Exponent CMS 0.96.3 and later versions stores sensitive user pages under the web document root with insufficient access control even though certain permissions are specified, which allows attackers to access the pages by browsing uploaded files. | Assigned (20051122) | None (candidate not yet proposed) | View | |
14971 | CVE-2005-3767 | Candidate | Exponent CMS 0.96.3 and later versions does not properly restrict the types of uploaded files, which allows remote attackers to upload and execute PHP files. | Assigned (20051122) | None (candidate not yet proposed) | View | |
14972 | CVE-2005-3768 | Candidate | Buffer overflow in the Internet Key Exchange version 1 (IKEv1) implementation in Symantec Dynamic VPN Services, as used in Enterprise Firewall, Gateway Security, and Firewall /VPN Appliance products, allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. | Assigned (20051122) | None (candidate not yet proposed) | View | |
14973 | CVE-2005-3769 | Candidate | SQL injection vulnerability in files.php in PHP Download Manager 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. | Assigned (20051122) | None (candidate not yet proposed) | View |
Page 18690 of 20943, showing 5 records out of 104715 total, starting on record 93446, ending on 93450