CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13643 | CVE-2005-2437 | Candidate | Website Baker Project does not properly verify the file extensions of uploaded files, which allows remote attackers to upload and execute arbitrary PHP code. | Assigned (20050803) | None (candidate not yet proposed) | View | |
13644 | CVE-2005-2438 | Candidate | Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier allows remote attackers to inject arbitrary Javascript via the BBCode color value. | Assigned (20050803) | None (candidate not yet proposed) | View | |
13645 | CVE-2005-2439 | Candidate | SQL injection vulnerability in UseBB 0.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search function. | Assigned (20050803) | None (candidate not yet proposed) | View | |
13646 | CVE-2005-2440 | Candidate | SQL injection vulnerability in login.asp in Thomson Web Skill Vantage Manager allows remote attackers to execute arbitrary SQL commands via the svmPassword parameter. | Assigned (20050803) | None (candidate not yet proposed) | View | |
13647 | CVE-2005-2441 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in VBzoom allow remote attackers to inject arbitrary web script and HTML via the (1) UserName parameter to profile.php or (2) UserID parameter to login.php. | Assigned (20050803) | None (candidate not yet proposed) | View |
Page 19055 of 20943, showing 5 records out of 104715 total, starting on record 95271, ending on 95275