CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13813  CVE-2005-2607  Candidate  PHP file include vulnerability in download.php in PHPSimplicity Simplicity oF Upload before 1.3.1 allows remote attackers to include arbitrary local and remote files via the language parameter and a terminating null ("%00") characters.  Assigned (20050817)  None (candidate not yet proposed)    View
13814  CVE-2005-2608  Candidate  SafeHTML before 1.3.5 does not properly filter script in UTF-7 and CSS comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks in vulnerable applications that use SafeHTML.  Assigned (20050817)  None (candidate not yet proposed)    View
13815  CVE-2005-2609  Candidate  index.php in VegaDNS 0.8.1, 0.9.8, and possibly other versions, allows remote attackers to obtain the full server path via an invalid VDNS_Sessid parameter.  Assigned (20050817)  None (candidate not yet proposed)    View
13816  CVE-2005-2610  Candidate  Cross-site scripting (XSS) vulnerability in index.php in VegaDNS 0.8.1, 0.9.8, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the message parameter.  Assigned (20050817)  None (candidate not yet proposed)    View
13817  CVE-2005-2611  Candidate  VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which allows remote attackers to read and write arbitrary files with the backup server.  Assigned (20050817)  None (candidate not yet proposed)    View

Page 18989 of 20943, showing 5 records out of 104715 total, starting on record 94941, ending on 94945

Actions