CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13639  CVE-2005-2433  Candidate  PhpList allows remote attackers to obtain sensitive information via a direct request to (1) about.php, (2) connect.php, (3) domainstats.php or (4) usercheck.php in public_html/lists/admin directory, (5) attributes.php, (6) dbcheck.php, (7) importcsv.php, (8) user.php, (9) usermgt.php, or (10) users.php in admin/commonlib/pages directory, (11) helloworld.php, or (12) sidebar.php in public_html/lists/admin/plugins directory, or (13) main.php in public_html/lists/admin/plugsins/defaultplugin directory, which reveal the path in an error message.  Assigned (20050803)  None (candidate not yet proposed)    View
13640  CVE-2005-2434  Candidate  Linksys WRT54G router uses the same private key and certificate for every router, which allows remote attackers to sniff the SSL connection and obtain sensitive information.  Assigned (20050803)  None (candidate not yet proposed)    View
13641  CVE-2005-2435  Candidate  Cross-site scripting (XSS) vulnerability in browse.php in Website Baker Project allows remote attackers to inject arbitrary web script or HTML via the dir parameter.  Assigned (20050803)  None (candidate not yet proposed)    View
13642  CVE-2005-2436  Candidate  browse.php in Website Baker Project allows remote attackers to obtain sensitive data via (1) a directory that does not exist in the dir parameter or (2) a direct request to certain php files, which reveal the path in an error message.  Assigned (20050803)  None (candidate not yet proposed)    View
13643  CVE-2005-2437  Candidate  Website Baker Project does not properly verify the file extensions of uploaded files, which allows remote attackers to upload and execute arbitrary PHP code.  Assigned (20050803)  None (candidate not yet proposed)    View

Page 1891 of 20943, showing 5 records out of 104715 total, starting on record 9451, ending on 9455

Actions