CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10710 | CVE-2004-2284 | Candidate | The read_list_from_file function in vacation.pl for OpenWebmail before 2.32 20040629 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename argument. | Assigned (20050719) | None (candidate not yet proposed) | View | |
13526 | CVE-2005-2320 | Candidate | WebCalendar before 1.0.0 does not properly restrict access to assistant_edit.php, which allows remote attackers to gain privileges. | Assigned (20050719) | None (candidate not yet proposed) | View | |
13527 | CVE-2005-2321 | Candidate | PHP remote file inclusion vulnerability in CaLogic 1.2.2 allows remote attackers to execute arbitrary code via the CLPATH parameter to (1) cl_minical.php, (2) clmcpreload.php, (3) mcconfig.php, or (4) mcpi-demo.php. | Assigned (20050719) | None (candidate not yet proposed) | View | |
13528 | CVE-2005-2322 | Candidate | Cross-site scripting (XSS) vulnerability in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allows remote attackers to inject arbitrary web script or HTML via the (1) viewuser_id or (2) group parameter to users.php. | Assigned (20050719) | None (candidate not yet proposed) | View | |
13529 | CVE-2005-2323 | Candidate | Multiple SQL injection vulnerabilities in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allow remote attackers to modify SQL statements via the (1) id parameter to viewattach.php, (2) viewuser_id parameter to users.php, or the (3) id or (4) forum parameter to viewforum.php. | Assigned (20050719) | None (candidate not yet proposed) | View |
Page 19085 of 20943, showing 5 records out of 104715 total, starting on record 95421, ending on 95425