CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13749  CVE-2005-2543  Candidate  Directory traversal vulnerability in wce.download.php in Comdev eCommerce 3.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the download parameter.  Assigned (20050810)  None (candidate not yet proposed)    View
13750  CVE-2005-2544  Candidate  PHP remote file inclusion vulnerability in config.php in Comdev eCommerce 3.0 allows remote attackers to execute arbitrary PHP code via the path[docroot] parameter.  Assigned (20050810)  None (candidate not yet proposed)    View
13751  CVE-2005-2545  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in PHPOpenChat 3.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content parameter to profile.php and profile_misc.php, (3) the profile fields in userpage.php, (4) subject or (5) body in mail.php, or (8) disinvited_chatter or (7) invited_chatter parameter to invite.php.  Assigned (20050810)  None (candidate not yet proposed)    View
13752  CVE-2005-2546  Candidate  Arab Portal 2.0 allows remote attackers to obtain sensitive information via a long (1) username or (2) password, which reveals the path in an error message when the undefined "errmsg" function is called.  Assigned (20050810)  None (candidate not yet proposed)    View
13696  CVE-2005-2490  Candidate  Stack-based buffer overflow in the sendmsg function call in the Linux kernel 2.6 before 2.6.13.1 allows local users execute arbitrary code by calling sendmsg and modifying the message contents in another thread.  Assigned (20050808)  None (candidate not yet proposed)    View

Page 19027 of 20943, showing 5 records out of 104715 total, starting on record 95131, ending on 95135

Actions