CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13762  CVE-2005-2556  Candidate  core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with register_globals enabled, allows remote attackers to connect to internal databases by modifying the g_db_type variable and monitoring the speed of responses, as identified by bug#0005956.  Assigned (20050816)  None (candidate not yet proposed)    View
13763  CVE-2005-2557  Candidate  Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the dir parameter, as identified by bug#0005959, and a different vulnerability than CVE-2005-3090.  Assigned (20050816)  None (candidate not yet proposed)    View
13764  CVE-2005-2558  Candidate  Stack-based buffer overflow in the init_syms function in MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta allows remote authenticated users who can create user-defined functions to execute arbitrary code via a long function_name field.  Assigned (20050816)  None (candidate not yet proposed)    View
13765  CVE-2005-2559  Candidate  doping.php in ePing plugin 1.02 and earlier for e107 portal allows remote attackers to execute arbitrary code or overwrite files via (1) shell metacharacters in the eping_count parameter or (2) restricted shell metacharacters such as ">" and "&" in the eping_host parameter, which is not handled by the validation function.  Assigned (20050816)  None (candidate not yet proposed)    View
13766  CVE-2005-2560  Candidate  Cross-site scripting (XSS) vulnerability in index.cfm in CFBB 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.  Assigned (20050816)  None (candidate not yet proposed)    View

Page 19006 of 20943, showing 5 records out of 104715 total, starting on record 95026, ending on 95030

Actions