CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14070  CVE-2005-2864  Candidate  URBAN 1.5.3_1 allows local users to overwrite arbitrary files via a symlink attack on the (1) high score or (2) save game files.  Assigned (20050908)  None (candidate not yet proposed)    View
14071  CVE-2005-2865  Candidate  Multiple PHP remote file inclusion vulnerabilities in aMember Pro 2.3.4 allow remote attackers to execute arbitrary PHP code via the config[root_dir] parameter to (1) mysql.inc.php, (2) efsnet.inc.php, (3) theinternetcommerce.inc.php, (4) cdg.inc.php, (5) compuworld.inc.php, (6) directone.inc.php, (7) authorize_aim.inc.php, (8) beanstream.inc.php, (9) config.inc.php, (10) eprocessingnetwork.inc.php, (11) eway.inc.php, (12) linkpoint.inc.php, (13) logiccommerce.inc.php, (14) netbilling.inc.php, (15) payflow_pro.inc.php, (16) paymentsgateway.inc.php, (17) payos.inc.php, (18) payready.inc.php, or (19) plugnplay.inc.php.  Assigned (20050908)  None (candidate not yet proposed)    View
14072  CVE-2005-2866  Candidate  Mercora IMRadio 4.0.0.0 stores usernames and passwords in plaintext in the MercoraClientProfiles registry key, which allows local users to gain privileges.  Assigned (20050908)  None (candidate not yet proposed)    View
14073  CVE-2005-2867  Candidate  SQL injection vulnerability in BlueWhaleCRM allows remote attackers to execute arbitrary SQL commands via the Account ID field.  Assigned (20050908)  None (candidate not yet proposed)    View
14074  CVE-2005-2868  Candidate  ZipTorrent 1.3.7.3 stores sensitive information in plaintext in the pref.txt file, which allows local users to obtain sensitive information such as proxy server information and passwords.  Assigned (20050908)  None (candidate not yet proposed)    View

Page 18919 of 20943, showing 5 records out of 104715 total, starting on record 94591, ending on 94595

Actions