CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13893 | CVE-2005-2687 | Candidate | PHP remote file inclusion vulnerability in SaveWebPortal 3.4 allows remote attackers to execute arbitrary PHP code via the (1) SITE_Path parameter to menu_dx.php or (2) CONTENTS_Dir parameter to menu_sx.php. | Assigned (20050824) | None (candidate not yet proposed) | View | |
13894 | CVE-2005-2688 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in SaveWebPortal 3.4 allow remote attackers to inject arbitrary web script or HTML via a large number of parameters to (1) footer.php, (2) header.php, (3) menu_dx.php, or (4) menu_sx.php, or Javascript code in the (5) HTTP_REFERER (referer) or (6) HTTP_USER_AGENT (user agent) fields. | Assigned (20050824) | None (candidate not yet proposed) | View | |
13895 | CVE-2005-2689 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.760-RC4b allows remote attackers to inject arbitrary web script or HTML via (1) the moderate parameter to the Comments module or (2) htmltext parameter to html/user.php. | Assigned (20050824) | None (candidate not yet proposed) | View | |
13896 | CVE-2005-2690 | Candidate | SQL injection vulnerability in the Downloads module in PostNuke 0.760-RC4b allows PostNuke administrators to execute arbitrary SQL commands via the show parameter to dl-viewdownload.php. | Assigned (20050824) | None (candidate not yet proposed) | View | |
13897 | CVE-2005-2691 | Candidate | includes/common.php in RunCMS 1.2 and earlier calls the extract function with EXTR_OVERWRITE on HTTP POST variables, which allows remote attackers to overwrite arbitrary variables, possibly allowing execution of arbitrary code. | Assigned (20050824) | None (candidate not yet proposed) | View |
Page 18951 of 20943, showing 5 records out of 104715 total, starting on record 94751, ending on 94755