CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13233 | CVE-2005-2027 | Candidate | Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 does not properly restrict certain debugging commands to the ADMIN account, which could allow attackers to obtain sensitive information or modify the registry. | Assigned (20050621) | None (candidate not yet proposed) | View | |
6066 | CVE-2002-1682 | Candidate | NewsReactor 1.0 uses a weak encryption scheme, which could allow local users to decrypt the passwords and gain access to other users" newsgroup accounts. | Assigned (20050621) | None (candidate not yet proposed) | View | |
13234 | CVE-2005-2028 | Candidate | SQL injection vulnerability in index.php for MercuryBoard 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header. | Assigned (20050621) | None (candidate not yet proposed) | View | |
6067 | CVE-2002-1683 | Candidate | Cross-site scripting (XSS) vulnerability in BadBlue Personal Edition 1.7.3 allows remote attackers to execute arbitrary script as other users by injecting script into the cleanSearchString() function. | Assigned (20050621) | None (candidate not yet proposed) | View | |
13235 | CVE-2005-2029 | Candidate | amaroK Web Frontend 1.3 stores the globals.inc file under the web root without a .php extension and insufficient access control, which allows remote attackers to obtain the database username and password via a direct request to the file. | Assigned (20050621) | None (candidate not yet proposed) | View |
Page 19247 of 20943, showing 5 records out of 104715 total, starting on record 96231, ending on 96235