CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13638  CVE-2005-2432  Candidate  SQL injection vulnerability in PhpList allows remote attackers to modify SQL statements via the id argument to admin pages such as (1) members or (2) admin.  Assigned (20050803)  None (candidate not yet proposed)    View
13639  CVE-2005-2433  Candidate  PhpList allows remote attackers to obtain sensitive information via a direct request to (1) about.php, (2) connect.php, (3) domainstats.php or (4) usercheck.php in public_html/lists/admin directory, (5) attributes.php, (6) dbcheck.php, (7) importcsv.php, (8) user.php, (9) usermgt.php, or (10) users.php in admin/commonlib/pages directory, (11) helloworld.php, or (12) sidebar.php in public_html/lists/admin/plugins directory, or (13) main.php in public_html/lists/admin/plugsins/defaultplugin directory, which reveal the path in an error message.  Assigned (20050803)  None (candidate not yet proposed)    View
13640  CVE-2005-2434  Candidate  Linksys WRT54G router uses the same private key and certificate for every router, which allows remote attackers to sniff the SSL connection and obtain sensitive information.  Assigned (20050803)  None (candidate not yet proposed)    View
13641  CVE-2005-2435  Candidate  Cross-site scripting (XSS) vulnerability in browse.php in Website Baker Project allows remote attackers to inject arbitrary web script or HTML via the dir parameter.  Assigned (20050803)  None (candidate not yet proposed)    View
13642  CVE-2005-2436  Candidate  browse.php in Website Baker Project allows remote attackers to obtain sensitive data via (1) a directory that does not exist in the dir parameter or (2) a direct request to certain php files, which reveal the path in an error message.  Assigned (20050803)  None (candidate not yet proposed)    View

Page 19054 of 20943, showing 5 records out of 104715 total, starting on record 95266, ending on 95270

Actions