CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13643  CVE-2005-2437  Candidate  Website Baker Project does not properly verify the file extensions of uploaded files, which allows remote attackers to upload and execute arbitrary PHP code.  Assigned (20050803)  None (candidate not yet proposed)    View
13644  CVE-2005-2438  Candidate  Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier allows remote attackers to inject arbitrary Javascript via the BBCode color value.  Assigned (20050803)  None (candidate not yet proposed)    View
13645  CVE-2005-2439  Candidate  SQL injection vulnerability in UseBB 0.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search function.  Assigned (20050803)  None (candidate not yet proposed)    View
13646  CVE-2005-2440  Candidate  SQL injection vulnerability in login.asp in Thomson Web Skill Vantage Manager allows remote attackers to execute arbitrary SQL commands via the svmPassword parameter.  Assigned (20050803)  None (candidate not yet proposed)    View
13647  CVE-2005-2441  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in VBzoom allow remote attackers to inject arbitrary web script and HTML via the (1) UserName parameter to profile.php or (2) UserID parameter to login.php.  Assigned (20050803)  None (candidate not yet proposed)    View

Page 19055 of 20943, showing 5 records out of 104715 total, starting on record 95271, ending on 95275

Actions