CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13503  CVE-2005-2297  Candidate  Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a large javascript parameter.  Assigned (20050719)  None (candidate not yet proposed)    View
10688  CVE-2004-2262  Candidate  ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php.  Assigned (20050719)  None (candidate not yet proposed)    View
13504  CVE-2005-2298  Candidate  BitDefender Engine 1.6.1 and earlier does not properly scan all attachments, which allows remote attackers to bypass virus scanning via begin and end commands in the body of the e-mail, which BitDefender treats as a uuencoded attachment and stops scanning afterwards.  Assigned (20050719)  None (candidate not yet proposed)    View
10689  CVE-2004-2263  Candidate  SQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to modify SQL statements via the vc2 cookie.  Assigned (20050719)  None (candidate not yet proposed)    View
13505  CVE-2005-2299  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Simple Message Board Version 2.0 Beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) FID parameter to forum.cfm, (2) UID parameter to user.cfm, (3) TID parameter to thread.cfm, or (4) PostDate parameter to search.cfm.  Assigned (20050719)  None (candidate not yet proposed)    View

Page 19076 of 20943, showing 5 records out of 104715 total, starting on record 95376, ending on 95380

Actions