CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13281  CVE-2005-2075  Candidate  PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to the filename in the administration/db_backups directory in PHP-Fusion 6.0 or the fusion_admin/db_backups directory in 5.0.  Assigned (20050629)  None (candidate not yet proposed)    View
13282  CVE-2005-2076  Candidate  HP Version Control Repository Manager (VCRM) before 2.1.1.730 does not properly handle the "@" character in a proxy password, which could allow attackers with physical access to obtain portions of the password when it is displayed to the screen.  Assigned (20050629)  None (candidate not yet proposed)    View
13283  CVE-2005-2077  Candidate  Cross-site scripting (XSS) vulnerability in error.asp for Hosting Controller allows remote attackers to inject arbitrary web script or HTML via the error parameter.  Assigned (20050629)  None (candidate not yet proposed)    View
13284  CVE-2005-2078  Candidate  BisonFTP Server V4R1 allows remote authenticated users to cause a denial of service via an invalid command with a long argument.  Assigned (20050629)  None (candidate not yet proposed)    View
13285  CVE-2005-2079  Candidate  Heap-based buffer overflow in the Admin Plus Pack Option for VERITAS Backup Exec 9.0 through 10.0 for Windows Servers allows remote attackers to execute arbitrary code.  Assigned (20050629)  None (candidate not yet proposed)    View

Page 19234 of 20943, showing 5 records out of 104715 total, starting on record 96166, ending on 96170

Actions