CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14155  CVE-2005-2949  Candidate  pam_per_user before 0.4 does not verify if the user name changes between authentication attempts and uses the same subrequest handle, which allows remote attackers or local users to login as other users by using certain applications that allow the username to be changed during authentication, such as /bin/login.  Assigned (20050916)  None (candidate not yet proposed)    View
14156  CVE-2005-2950  Candidate  Cross-site scripting (XSS) vulnerability in Sawmill 7.0.0 through 7.1.13 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP GET request.  Assigned (20050916)  None (candidate not yet proposed)    View
14157  CVE-2005-2951  Candidate  Directory traversal vulnerability in security.inc.php in AzDGDatingLite 2.1.3, and possibly earlier versions, allows remote attackers to execute arbitrary PHP commands via ".." sequences and "%00" (trailing null byte) characters in the l parameter, which is used in an include_once statement.  Assigned (20050916)  None (candidate not yet proposed)    View
14158  CVE-2005-2952  Candidate  Directory traversal vulnerability in s.pl in Subscribe Me Pro 2.044.09P and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the l parameter.  Assigned (20050916)  None (candidate not yet proposed)    View
14159  CVE-2005-2953  Candidate  Cross-site scripting (XSS) vulnerability in merchant.mvc in MIVA Merchant 5 allows remote attackers to inject arbitrary web script or HTML via the Customer_Login parameter.  Assigned (20050916)  None (candidate not yet proposed)    View

Page 18898 of 20943, showing 5 records out of 104715 total, starting on record 94486, ending on 94490

Actions