CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
14617 | CVE-2005-3411 | Candidate | Cross-site scripting (XSS) vulnerability in post.asp in Snitz Forums 2000 3.4.05 allows remote attackers to inject arbitrary web script or HTML via the type parameter in a Topic method. | Assigned (20051101) | None (candidate not yet proposed) | View | |
14618 | CVE-2005-3412 | Candidate | Cross-site scripting (XSS) vulnerability in Elite Forum 1.0.0.0 allows remote attackers to inject arbitrary web script or HTML via a Post Reply to a topic, in which the reply contains a javascript: URL in an <img> tag. | Assigned (20051101) | None (candidate not yet proposed) | View | |
14619 | CVE-2005-3413 | Candidate | Cross-site scripting (XSS) vulnerability in desktop.php in eyeOS 0.8.4 allows remote attackers to inject arbitrary web script or HTML via the motd parameter. | Assigned (20051101) | None (candidate not yet proposed) | View | |
14620 | CVE-2005-3414 | Candidate | eyeOS 0.8.4 stores usrinfo.xml under the web document root with insufficient access control, which allows remote attackers to obtain user credentials. | Assigned (20051101) | None (candidate not yet proposed) | View | |
14621 | CVE-2005-3415 | Candidate | phpBB 2.0.17 and earlier allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GET/POST/COOKIE (GPC) variable and a GLOBALS[] variable with the same name, which causes phpBB to unset the GLOBALS[] variable but not the GPC variable. | Assigned (20051101) | None (candidate not yet proposed) | View |
Page 18796 of 20943, showing 5 records out of 104715 total, starting on record 93976, ending on 93980