CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13618  CVE-2005-2412  Candidate  PHP remote file inclusion vulnerability in block.php in PHP FirstPost allows remote attackers to execute arbitrary PHP code via the Include parameter.  Assigned (20050803)  None (candidate not yet proposed)    View
13619  CVE-2005-2413  Candidate  PHP remote file inclusion vulnerability in apa_phpinclude.inc.php in Atomic Photo Album (APA) allows remote attackers to execute arbitrary PHP code via the apa_module_basedir parameter.  Assigned (20050803)  None (candidate not yet proposed)    View
13620  CVE-2005-2414  Candidate  Race condition in the xpcom library, as used by web browsers such as Firefox, Mozilla, Netscape, and Galeon, allows remote attackers to cause a denial of service (application crash) via a large HTML file that loads a DOM call from within nested DIV tags, which causes part of the currently rendering page and referenced objects to be deleted.  Assigned (20050803)  None (candidate not yet proposed)    View
13621  CVE-2005-2415  Candidate  Multiple SQL injection vulnerabilities in Contrexx before 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) value parameter to the poll module or (2) pId parameter to the gallery module.  Assigned (20050803)  None (candidate not yet proposed)    View
13622  CVE-2005-2416  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module.  Assigned (20050803)  None (candidate not yet proposed)    View

Page 19050 of 20943, showing 5 records out of 104715 total, starting on record 95246, ending on 95250

Actions