CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14405  CVE-2005-3199  Candidate  Multiple SQL injection vulnerabilities in aradmin.asp for aspReady FAQ allow remote attackers to execute arbitrary SQL commands, possibly via the (1) txtLogin and (2) txtPassword parameters.  Assigned (20051014)  None (candidate not yet proposed)    View
14406  CVE-2005-3200  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the sitetitle parameter in header.php and (2) the version and (3) query_count parameters in footer.php.  Assigned (20051014)  None (candidate not yet proposed)    View
14407  CVE-2005-3201  Candidate  SQL injection vulnerability in news.php for Utopia News Pro (UNP) 1.1.3, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary SQL via the newsid parameter.  Assigned (20051014)  None (candidate not yet proposed)    View
14408  CVE-2005-3202  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 allow remote attackers to inject arbitrary web script or HTML, and subsequently execute SQL statements via the (1) p or (2) p_t02 parameters.  Assigned (20051014)  None (candidate not yet proposed)    View
14409  CVE-2005-3203  Candidate  The manual installation of Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 stores the SYS password in install.lst in plaintext, which allows local users to gain privileges.  Assigned (20051014)  None (candidate not yet proposed)    View

Page 18842 of 20943, showing 5 records out of 104715 total, starting on record 94206, ending on 94210

Actions