CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13988  CVE-2005-2782  Candidate  PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an "ftp://" URL in the alpath parameter, which bypasses the incomplete blacklist that only checks for "http" and "https" URLs.  Assigned (20050902)  None (candidate not yet proposed)    View
13989  CVE-2005-2783  Candidate  Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML via nested, malformed URL BBCode tags.  Assigned (20050902)  None (candidate not yet proposed)    View
13990  CVE-2005-2784  Candidate  SQL injection vulnerability in the login function for the administration login panel in cosmoshop 8.10.78 allows remote attackers to execute arbitrary SQL commands and bypass authentication via unspecified vectors.  Assigned (20050902)  None (candidate not yet proposed)    View
13991  CVE-2005-2785  Candidate  cosmoshop 8.10.78 and earlier stores passwords in plaintext in the database, which allows local users to obtain sensitive information.  Assigned (20050902)  None (candidate not yet proposed)    View
13992  CVE-2005-2786  Candidate  Directory traversal vulnerability in bestmail_edit.cgi in cosmoshop 8.10.78 and earlier allows remote administrators to read arbitrary files via ".." sequences in the file parameter.  Assigned (20050902)  None (candidate not yet proposed)    View

Page 18933 of 20943, showing 5 records out of 104715 total, starting on record 94661, ending on 94665

Actions