CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13604  CVE-2005-2398  Candidate  Multiple SQL injection vulnerabilities in PHP Surveyor 0.98 allows remote attackers to execute arbitrary SQL commands via (1) the sid, start, and id parameters to browse.php, the sid parameter to (2) dataentry.php, (3) export.php, (4) admin.php, (5) conditions.php, (6) spss.php, (7) deletesurvey.php, (8) dumpsurvey.php, or (9) statistics.php, or the lid parameter to (10) labels.php or (11) dumplabel.php.  Assigned (20050727)  None (candidate not yet proposed)    View
13605  CVE-2005-2399  Candidate  PHP Surveyor 0.98 allows remote attackers to trigger SQL errors via missing parameters to (1) browse.php, (2) export.php, (3) conditions.php, or (4) spss.php.  Assigned (20050727)  None (candidate not yet proposed)    View
13606  CVE-2005-2400  Candidate  The inc.login.php scripts in PHPFinance 0.3 allows remote attackers to bypass the login and gain privileges.  Assigned (20050727)  None (candidate not yet proposed)    View
13607  CVE-2005-2401  Candidate  PHP-Fusion allows remote attackers to inject arbitrary Cascading Style Sheets (CSS) via the BBCode color tag.  Assigned (20050727)  None (candidate not yet proposed)    View
13608  CVE-2005-2402  Candidate  Cross-site scripting (XSS) vulnerability in search.php in PHPSiteSearch 1.7.7d allows remote attackers to inject arbitrary web script or HTML via the query parameter.  Assigned (20050727)  None (candidate not yet proposed)    View

Page 1884 of 20943, showing 5 records out of 104715 total, starting on record 9416, ending on 9420

Actions