CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13463  CVE-2005-2257  Candidate  The saveProfile function in PhpSlash 0.8.0 allows remote attackers to modify arbitrary profiles and gain privileges by modifying the author_id parameter.  Assigned (20050713)  None (candidate not yet proposed)    View
13464  CVE-2005-2258  Candidate  PHP remote file inclusion vulnerability in photolist.inc.php in Squito Gallery 1.33 allows remote attackers to execute arbitrary code via the photoroot parameter.  Assigned (20050713)  None (candidate not yet proposed)    View
13465  CVE-2005-2259  Candidate  The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute arbitrary code via shell metacharacters in the DISPCLOSED parameter.  Assigned (20050713)  None (candidate not yet proposed)    View
13466  CVE-2005-2260  Candidate  The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-generated events and untrusted synthetic events, which makes it easier for remote attackers to perform dangerous actions that normally could only be performed manually by the user.  Assigned (20050713)  None (candidate not yet proposed)    View
13467  CVE-2005-2261  Candidate  Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection.  Assigned (20050713)  None (candidate not yet proposed)    View

Page 19137 of 20943, showing 5 records out of 104715 total, starting on record 95681, ending on 95685

Actions