CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10710  CVE-2004-2284  Candidate  The read_list_from_file function in vacation.pl for OpenWebmail before 2.32 20040629 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename argument.  Assigned (20050719)  None (candidate not yet proposed)    View
13526  CVE-2005-2320  Candidate  WebCalendar before 1.0.0 does not properly restrict access to assistant_edit.php, which allows remote attackers to gain privileges.  Assigned (20050719)  None (candidate not yet proposed)    View
13527  CVE-2005-2321  Candidate  PHP remote file inclusion vulnerability in CaLogic 1.2.2 allows remote attackers to execute arbitrary code via the CLPATH parameter to (1) cl_minical.php, (2) clmcpreload.php, (3) mcconfig.php, or (4) mcpi-demo.php.  Assigned (20050719)  None (candidate not yet proposed)    View
13528  CVE-2005-2322  Candidate  Cross-site scripting (XSS) vulnerability in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allows remote attackers to inject arbitrary web script or HTML via the (1) viewuser_id or (2) group parameter to users.php.  Assigned (20050719)  None (candidate not yet proposed)    View
13529  CVE-2005-2323  Candidate  Multiple SQL injection vulnerabilities in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allow remote attackers to modify SQL statements via the (1) id parameter to viewattach.php, (2) viewuser_id parameter to users.php, or the (3) id or (4) forum parameter to viewforum.php.  Assigned (20050719)  None (candidate not yet proposed)    View

Page 19085 of 20943, showing 5 records out of 104715 total, starting on record 95421, ending on 95425

Actions