CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13777  CVE-2005-2571  Candidate  FunkBoard 0.66CF, and possibly earlier versions, does not properly restrict access to the (1) admin/mysql_install.php and (2) admin/pg_install.php scripts, which allows attackers to obtain the database username and password or inject arbitrary PHP code into info.php.  Assigned (20050816)  None (candidate not yet proposed)    View
13778  CVE-2005-2572  Candidate  MySQL, when running on Windows, allows remote authenticated users with insert privileges on the mysql.func table to cause a denial of service (server hang) and possibly execute arbitrary code via (1) a request for a non-library file, which causes the Windows LoadLibraryEx function to block, or (2) a request for a function in a library that has the XXX_deinit or XXX_init functions defined but is not tailored for mySQL, such as jpeg1x32.dll and jpeg2x32.dll.  Assigned (20050816)  None (candidate not yet proposed)    View
13779  CVE-2005-2573  Candidate  The mysql_create_function function in sql_udf.cc for MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta, when running on Windows, uses an incomplete blacklist in a directory traversal check, which allows attackers to include arbitrary files via the backslash () character.  Assigned (20050816)  None (candidate not yet proposed)    View
13780  CVE-2005-2574  Candidate  xmb.php in XMB Forum 1.9.1 extracts and defines all provided variables, which allows remote attackers to modify arbitrary server variables such as _SERVER[REMOTE_ADDR].  Assigned (20050816)  None (candidate not yet proposed)    View
13781  CVE-2005-2575  Candidate  SQL injection vulnerability in u2u.inc.php in XMB Forum 1.9.1 allows remote attackers to execute arbitrary SQL commands via certain values that are inserted into the $in variable.  Assigned (20050816)  None (candidate not yet proposed)    View

Page 19009 of 20943, showing 5 records out of 104715 total, starting on record 95041, ending on 95045

Actions