CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13495  CVE-2005-2289  Candidate  PHPCounter 7.2 allows remote attackers to obtain sensitive information via a direct request to prelims.php, which reveals the path in an error message.  Assigned (20050717)  None (candidate not yet proposed)    View
10680  CVE-2004-2254  Candidate  SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration interface via a direct request to admin.cgi with a modified utoken parameter.  Assigned (20050717)  None (candidate not yet proposed)    View
13496  CVE-2005-2290  Candidate  wps_shop.cgi in WPS Web Portal System 0.7.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art and (2) cat variables.  Assigned (20050717)  None (candidate not yet proposed)    View
10681  CVE-2004-2255  Candidate  Directory traversal vulnerability in phpMyFAQ 1.3.12 allows remote attackers to read arbitrary files, and possibly execute local PHP files, via the action variable, which is used as part of a template filename.  Assigned (20050717)  None (candidate not yet proposed)    View
13497  CVE-2005-2291  Candidate  Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 passes the cleartext password as a parameter when starting sqlplus, which allows local users to gain sensitive information.  Assigned (20050717)  None (candidate not yet proposed)    View

Page 19097 of 20943, showing 5 records out of 104715 total, starting on record 95481, ending on 95485

Actions