CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13604 | CVE-2005-2398 | Candidate | Multiple SQL injection vulnerabilities in PHP Surveyor 0.98 allows remote attackers to execute arbitrary SQL commands via (1) the sid, start, and id parameters to browse.php, the sid parameter to (2) dataentry.php, (3) export.php, (4) admin.php, (5) conditions.php, (6) spss.php, (7) deletesurvey.php, (8) dumpsurvey.php, or (9) statistics.php, or the lid parameter to (10) labels.php or (11) dumplabel.php. | Assigned (20050727) | None (candidate not yet proposed) | View | |
13605 | CVE-2005-2399 | Candidate | PHP Surveyor 0.98 allows remote attackers to trigger SQL errors via missing parameters to (1) browse.php, (2) export.php, (3) conditions.php, or (4) spss.php. | Assigned (20050727) | None (candidate not yet proposed) | View | |
13606 | CVE-2005-2400 | Candidate | The inc.login.php scripts in PHPFinance 0.3 allows remote attackers to bypass the login and gain privileges. | Assigned (20050727) | None (candidate not yet proposed) | View | |
13607 | CVE-2005-2401 | Candidate | PHP-Fusion allows remote attackers to inject arbitrary Cascading Style Sheets (CSS) via the BBCode color tag. | Assigned (20050727) | None (candidate not yet proposed) | View | |
13608 | CVE-2005-2402 | Candidate | Cross-site scripting (XSS) vulnerability in search.php in PHPSiteSearch 1.7.7d allows remote attackers to inject arbitrary web script or HTML via the query parameter. | Assigned (20050727) | None (candidate not yet proposed) | View |
Page 1884 of 20943, showing 5 records out of 104715 total, starting on record 9416, ending on 9420