CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14465  CVE-2005-3259  Candidate  Multiple SQL injection vulnerabilities in versatileBulletinBoard (vBB) 1.0.0 RC2 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) login field, (2) "search this thread" feature, (3) "search for posts" feature, (4) "forgot password" feature, (5) list parameter in userlistpre.php, and the (6) select, (7) categ, and (8) to parameters in index.php.  Assigned (20051020)  None (candidate not yet proposed)    View
14466  CVE-2005-3260  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in versatileBulletinBoard (vBB) 1.0.0 RC2 allow remote attackers to inject arbitrary web script or HTML via (1) the url parameter in dereferrer.php and (2) the file parameter in imagewin.php.  Assigned (20051020)  None (candidate not yet proposed)    View
14467  CVE-2005-3261  Candidate  getversions.php in versatileBulletinBoard (vBB) 1.0.0 RC2 lists the versions of all installed scripts, which allows remote attackers to obtain sensitive information via a direct request.  Assigned (20051020)  None (candidate not yet proposed)    View
14468  CVE-2005-3262  Candidate  Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via format string specifiers in a UUE/XXE file, which are not properly handled when WinRAR displays diagnostic errors related to an invalid filename.  Assigned (20051020)  None (candidate not yet proposed)    View
14469  CVE-2005-3263  Candidate  Stack-based buffer overflow in UNACEV2.DLL for RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via an ACE archive containing a file with a long name.  Assigned (20051020)  None (candidate not yet proposed)    View

Page 18833 of 20943, showing 5 records out of 104715 total, starting on record 94161, ending on 94165

Actions