CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
14021 | CVE-2005-2815 | Candidate | print.php in FlatNuke 2.5.6 allows remote attackers to obtain sensitive information (path disclosure on error) or cause a denial of service (resource consumption) via an MS-DOS device name in the news parameter to print.php, such as (1) AUX, (2) CON, (3) PRN, (4) COM1, or (5) LPT1. | Assigned (20050907) | None (candidate not yet proposed) | View | |
14022 | CVE-2005-2816 | Candidate | Cross-site scripting (XSS) vulnerability in Greymatter allows remote attackers to inject arbitrary web script or HTML via a post comment, which is recorded in a log file but not properly handled when the administrator uses "View Control Panel Log" to read the log file. | Assigned (20050907) | None (candidate not yet proposed) | View | |
14023 | CVE-2005-2817 | Candidate | Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive information of forum visitors such as IP address and user agent, as demonstrated using a PHP script on a malicious server. | Assigned (20050907) | None (candidate not yet proposed) | View | |
14024 | CVE-2005-2818 | Candidate | Cross-site scripting (XSS) vulnerability in DownFile 1.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter to (1) email.php,(2) index.php, (3) del.php, or (4) add_form.php. | Assigned (20050907) | None (candidate not yet proposed) | View | |
14025 | CVE-2005-2819 | Candidate | DownFile 1.3 allows remote attackers to gain administrator privileges via a direct request to (1) update.php, (2) del.php, and (3) add_form.php. | Assigned (20050907) | None (candidate not yet proposed) | View |
Page 18922 of 20943, showing 5 records out of 104715 total, starting on record 94606, ending on 94610