CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14969  CVE-2005-3765  Candidate  Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows remote attackers to execute arbitrary code.  Assigned (20051122)  None (candidate not yet proposed)    View
14970  CVE-2005-3766  Candidate  Exponent CMS 0.96.3 and later versions stores sensitive user pages under the web document root with insufficient access control even though certain permissions are specified, which allows attackers to access the pages by browsing uploaded files.  Assigned (20051122)  None (candidate not yet proposed)    View
14971  CVE-2005-3767  Candidate  Exponent CMS 0.96.3 and later versions does not properly restrict the types of uploaded files, which allows remote attackers to upload and execute PHP files.  Assigned (20051122)  None (candidate not yet proposed)    View
14972  CVE-2005-3768  Candidate  Buffer overflow in the Internet Key Exchange version 1 (IKEv1) implementation in Symantec Dynamic VPN Services, as used in Enterprise Firewall, Gateway Security, and Firewall /VPN Appliance products, allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.  Assigned (20051122)  None (candidate not yet proposed)    View
14973  CVE-2005-3769  Candidate  SQL injection vulnerability in files.php in PHP Download Manager 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.  Assigned (20051122)  None (candidate not yet proposed)    View

Page 18690 of 20943, showing 5 records out of 104715 total, starting on record 93446, ending on 93450

Actions