CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14571  CVE-2005-3365  Candidate  Multiple SQL injection vulnerabilities in DCP-Portal 6 and earlier allow remote attackers to execute arbitrary SQL commands, possibly requiring encoded characters, via (1) the name parameter in register.php, (2) the email parameter in lostpassword.php, (3) the year parameter in calendar.php, and the (4) cid parameter to index.php. NOTE: the mid parameter for forums.php is already associated with CVE-2005-0454. NOTE: the index.php/cid vector was later reported to affect 6.11.  Assigned (20051029)  None (candidate not yet proposed)    View
14572  CVE-2005-3366  Candidate  PHP file inclusion vulnerability in index.php in PHP iCalendar 2.0a2 through 2.0.1 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the phpicalendar cookie. NOTE: this is not a cross-site scripting (XSS) issue as claimed by the original researcher.  Assigned (20051029)  None (candidate not yet proposed)    View
14573  CVE-2005-3367  Candidate  Cross-site scripting (XSS) vulnerability in journal.php in SparkleBlog 2.1 allows remote attackers to inject arbitrary web script or HTML via the name field.  Assigned (20051029)  None (candidate not yet proposed)    View
14574  CVE-2005-3368  Candidate  Cross-site scripting (XSS) vulnerability in the Search_Enhanced module in PHP-Nuke 7.9 allows remote attackers to inject arbitrary web script or HTML via the query parameter.  Assigned (20051029)  None (candidate not yet proposed)    View
14575  CVE-2005-3369  Candidate  Multiple SQL injection vulnerabilities in the Info-DB module (info_db.php) in Woltlab Burning Board 2.7 and earlier allow remote attackers to execute arbitrary SQL commands and possibly upload files via the (1) fileid and (2) subkatid parameters.  Assigned (20051029)  None (candidate not yet proposed)    View

Page 18800 of 20943, showing 5 records out of 104715 total, starting on record 93996, ending on 94000

Actions