CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14021  CVE-2005-2815  Candidate  print.php in FlatNuke 2.5.6 allows remote attackers to obtain sensitive information (path disclosure on error) or cause a denial of service (resource consumption) via an MS-DOS device name in the news parameter to print.php, such as (1) AUX, (2) CON, (3) PRN, (4) COM1, or (5) LPT1.  Assigned (20050907)  None (candidate not yet proposed)    View
14022  CVE-2005-2816  Candidate  Cross-site scripting (XSS) vulnerability in Greymatter allows remote attackers to inject arbitrary web script or HTML via a post comment, which is recorded in a log file but not properly handled when the administrator uses "View Control Panel Log" to read the log file.  Assigned (20050907)  None (candidate not yet proposed)    View
14023  CVE-2005-2817  Candidate  Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive information of forum visitors such as IP address and user agent, as demonstrated using a PHP script on a malicious server.  Assigned (20050907)  None (candidate not yet proposed)    View
14024  CVE-2005-2818  Candidate  Cross-site scripting (XSS) vulnerability in DownFile 1.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter to (1) email.php,(2) index.php, (3) del.php, or (4) add_form.php.  Assigned (20050907)  None (candidate not yet proposed)    View
14025  CVE-2005-2819  Candidate  DownFile 1.3 allows remote attackers to gain administrator privileges via a direct request to (1) update.php, (2) del.php, and (3) add_form.php.  Assigned (20050907)  None (candidate not yet proposed)    View

Page 18922 of 20943, showing 5 records out of 104715 total, starting on record 94606, ending on 94610

Actions