CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14367  CVE-2005-3161  Candidate  Multiple SQL injection vulnerabilities in PHP-Fusion before 6.00.110 allow remote attackers to execute arbitrary SQL commands via (1) the activate parameter in register.php and (2) the cat_id parameter in faq.php.  Assigned (20051006)  None (candidate not yet proposed)    View
14368  CVE-2005-3162  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-3160. Reason: this candidate is a duplicate of CVE-2005-3160. Notes: All CVE users should reference CVE-2005-3160 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20051006)  None (candidate not yet proposed)    View
14369  CVE-2005-3163  Candidate  Unspecified vulnerability in Polipo 0.9.8 and earlier allows attackers to read files outside of the web root.  Assigned (20051006)  None (candidate not yet proposed)    View
14370  CVE-2005-3164  Candidate  The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request, possibly related to Java Servlet pages.  Assigned (20051006)  None (candidate not yet proposed)    View
14371  CVE-2005-3165  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.4.9 allow remote attackers to inject arbitrary web script or HTML via (1) <math> tags or (2) Extension or <nowiki> sections that "bypass HTML style attribute restrictions" that are intended to protect against XSS vulnerabilities in Internet Explorer clients.  Assigned (20051006)  None (candidate not yet proposed)    View

Page 18853 of 20943, showing 5 records out of 104715 total, starting on record 94261, ending on 94265

Actions