CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13233  CVE-2005-2027  Candidate  Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 does not properly restrict certain debugging commands to the ADMIN account, which could allow attackers to obtain sensitive information or modify the registry.  Assigned (20050621)  None (candidate not yet proposed)    View
6066  CVE-2002-1682  Candidate  NewsReactor 1.0 uses a weak encryption scheme, which could allow local users to decrypt the passwords and gain access to other users" newsgroup accounts.  Assigned (20050621)  None (candidate not yet proposed)    View
13234  CVE-2005-2028  Candidate  SQL injection vulnerability in index.php for MercuryBoard 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.  Assigned (20050621)  None (candidate not yet proposed)    View
6067  CVE-2002-1683  Candidate  Cross-site scripting (XSS) vulnerability in BadBlue Personal Edition 1.7.3 allows remote attackers to execute arbitrary script as other users by injecting script into the cleanSearchString() function.  Assigned (20050621)  None (candidate not yet proposed)    View
13235  CVE-2005-2029  Candidate  amaroK Web Frontend 1.3 stores the globals.inc file under the web root without a .php extension and insufficient access control, which allows remote attackers to obtain the database username and password via a direct request to the file.  Assigned (20050621)  None (candidate not yet proposed)    View

Page 19247 of 20943, showing 5 records out of 104715 total, starting on record 96231, ending on 96235

Actions