CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14099  CVE-2005-2893  Candidate  Direct static code injection vulnerability in setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via the username (u parameter), which is directly injected into a file that is later executed upon login.  Assigned (20050914)  None (candidate not yet proposed)    View
14100  CVE-2005-2894  Candidate  Cross-site scripting (XSS) vulnerability in the user registration in PBLang 4.65, and possibly earlier versions, allows remote attackers to inject arbitrary web script or PHP via the location field.  Assigned (20050914)  None (candidate not yet proposed)    View
14101  CVE-2005-2895  Candidate  setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to obtain sensitive information via a %00 (a null byte) in the u parameter, which reveals the path in an error message.  Assigned (20050914)  None (candidate not yet proposed)    View
14102  CVE-2005-2896  Candidate  SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_userpw parameter to startup.php, (2) cat, (3) id, or (4) stof parameter to news.php, or (5) id parameter to print.php.  Assigned (20050914)  None (candidate not yet proposed)    View
14103  CVE-2005-2897  Candidate  WEB//NEWS 1.4 allows remote attackers to obtain sensitive information via a direct request to files in the actions directory, which reveal the path in an error message, as demonstrated using cat.add.php.  Assigned (20050914)  None (candidate not yet proposed)    View

Page 18908 of 20943, showing 5 records out of 104715 total, starting on record 94536, ending on 94540

Actions