CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13618 | CVE-2005-2412 | Candidate | PHP remote file inclusion vulnerability in block.php in PHP FirstPost allows remote attackers to execute arbitrary PHP code via the Include parameter. | Assigned (20050803) | None (candidate not yet proposed) | View | |
13619 | CVE-2005-2413 | Candidate | PHP remote file inclusion vulnerability in apa_phpinclude.inc.php in Atomic Photo Album (APA) allows remote attackers to execute arbitrary PHP code via the apa_module_basedir parameter. | Assigned (20050803) | None (candidate not yet proposed) | View | |
13620 | CVE-2005-2414 | Candidate | Race condition in the xpcom library, as used by web browsers such as Firefox, Mozilla, Netscape, and Galeon, allows remote attackers to cause a denial of service (application crash) via a large HTML file that loads a DOM call from within nested DIV tags, which causes part of the currently rendering page and referenced objects to be deleted. | Assigned (20050803) | None (candidate not yet proposed) | View | |
13621 | CVE-2005-2415 | Candidate | Multiple SQL injection vulnerabilities in Contrexx before 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) value parameter to the poll module or (2) pId parameter to the gallery module. | Assigned (20050803) | None (candidate not yet proposed) | View | |
13622 | CVE-2005-2416 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module. | Assigned (20050803) | None (candidate not yet proposed) | View |
Page 19050 of 20943, showing 5 records out of 104715 total, starting on record 95246, ending on 95250