CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13353  CVE-2005-2147  Candidate  Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer scripts.  Assigned (20050706)  None (candidate not yet proposed)    View
13354  CVE-2005-2148  Candidate  Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitrary commands or SQL by sending a legitimate value in a POST request or cookie, then specifying the attack string in the URL, which causes the get_request_var function to return the wrong value in the $_REQUEST variable, which is cleansed while the original malicious $_GET value remains unmodified, as demonstrated in (1) graph_image.php and (2) graph.php.  Assigned (20050706)  None (candidate not yet proposed)    View
13355  CVE-2005-2149  Candidate  config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.  Assigned (20050706)  None (candidate not yet proposed)    View
13356  CVE-2005-2150  Candidate  Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via eventlog.  Assigned (20050706)  None (candidate not yet proposed)    View
13357  CVE-2005-2151  Candidate  spf.c in Courier Mail Server does not properly handle DNS failures when looking up Sender Policy Framework (SPF) records, which could allow attackers to cause memory corruption.  Assigned (20050706)  None (candidate not yet proposed)    View

Page 19168 of 20943, showing 5 records out of 104715 total, starting on record 95836, ending on 95840

Actions