CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13463 | CVE-2005-2257 | Candidate | The saveProfile function in PhpSlash 0.8.0 allows remote attackers to modify arbitrary profiles and gain privileges by modifying the author_id parameter. | Assigned (20050713) | None (candidate not yet proposed) | View | |
13464 | CVE-2005-2258 | Candidate | PHP remote file inclusion vulnerability in photolist.inc.php in Squito Gallery 1.33 allows remote attackers to execute arbitrary code via the photoroot parameter. | Assigned (20050713) | None (candidate not yet proposed) | View | |
13465 | CVE-2005-2259 | Candidate | The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute arbitrary code via shell metacharacters in the DISPCLOSED parameter. | Assigned (20050713) | None (candidate not yet proposed) | View | |
13466 | CVE-2005-2260 | Candidate | The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-generated events and untrusted synthetic events, which makes it easier for remote attackers to perform dangerous actions that normally could only be performed manually by the user. | Assigned (20050713) | None (candidate not yet proposed) | View | |
13467 | CVE-2005-2261 | Candidate | Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection. | Assigned (20050713) | None (candidate not yet proposed) | View |
Page 19137 of 20943, showing 5 records out of 104715 total, starting on record 95681, ending on 95685