CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13638 | CVE-2005-2432 | Candidate | SQL injection vulnerability in PhpList allows remote attackers to modify SQL statements via the id argument to admin pages such as (1) members or (2) admin. | Assigned (20050803) | None (candidate not yet proposed) | View | |
13639 | CVE-2005-2433 | Candidate | PhpList allows remote attackers to obtain sensitive information via a direct request to (1) about.php, (2) connect.php, (3) domainstats.php or (4) usercheck.php in public_html/lists/admin directory, (5) attributes.php, (6) dbcheck.php, (7) importcsv.php, (8) user.php, (9) usermgt.php, or (10) users.php in admin/commonlib/pages directory, (11) helloworld.php, or (12) sidebar.php in public_html/lists/admin/plugins directory, or (13) main.php in public_html/lists/admin/plugsins/defaultplugin directory, which reveal the path in an error message. | Assigned (20050803) | None (candidate not yet proposed) | View | |
13640 | CVE-2005-2434 | Candidate | Linksys WRT54G router uses the same private key and certificate for every router, which allows remote attackers to sniff the SSL connection and obtain sensitive information. | Assigned (20050803) | None (candidate not yet proposed) | View | |
13641 | CVE-2005-2435 | Candidate | Cross-site scripting (XSS) vulnerability in browse.php in Website Baker Project allows remote attackers to inject arbitrary web script or HTML via the dir parameter. | Assigned (20050803) | None (candidate not yet proposed) | View | |
13642 | CVE-2005-2436 | Candidate | browse.php in Website Baker Project allows remote attackers to obtain sensitive data via (1) a directory that does not exist in the dir parameter or (2) a direct request to certain php files, which reveal the path in an error message. | Assigned (20050803) | None (candidate not yet proposed) | View |
Page 19054 of 20943, showing 5 records out of 104715 total, starting on record 95266, ending on 95270