CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
14099 | CVE-2005-2893 | Candidate | Direct static code injection vulnerability in setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via the username (u parameter), which is directly injected into a file that is later executed upon login. | Assigned (20050914) | None (candidate not yet proposed) | View | |
14100 | CVE-2005-2894 | Candidate | Cross-site scripting (XSS) vulnerability in the user registration in PBLang 4.65, and possibly earlier versions, allows remote attackers to inject arbitrary web script or PHP via the location field. | Assigned (20050914) | None (candidate not yet proposed) | View | |
14101 | CVE-2005-2895 | Candidate | setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to obtain sensitive information via a %00 (a null byte) in the u parameter, which reveals the path in an error message. | Assigned (20050914) | None (candidate not yet proposed) | View | |
14102 | CVE-2005-2896 | Candidate | SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_userpw parameter to startup.php, (2) cat, (3) id, or (4) stof parameter to news.php, or (5) id parameter to print.php. | Assigned (20050914) | None (candidate not yet proposed) | View | |
14103 | CVE-2005-2897 | Candidate | WEB//NEWS 1.4 allows remote attackers to obtain sensitive information via a direct request to files in the actions directory, which reveal the path in an error message, as demonstrated using cat.add.php. | Assigned (20050914) | None (candidate not yet proposed) | View |
Page 18908 of 20943, showing 5 records out of 104715 total, starting on record 94536, ending on 94540