CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6068 | CVE-2002-1684 | Candidate | Directory traversal vulnerability in (1) Deerfield D2Gfx 1.0.2 or (2) BadBlue Enterprise Edition 1.5.x and BadBlue Personal Edition 1.5.6 allows remote attackers to read arbitrary files via a ../ (dot dot slash) in the script used to read Microsoft Office documents. | Assigned (20050621) | None (candidate not yet proposed) | View | |
13236 | CVE-2005-2030 | Candidate | Ultimate PHP Board (UPB) 1.9.6 GOLD uses weak encryption for passwords in the users.dat file, which allows attackers to easily decrypt the passwords and gain privileges, possibly after exploiting CVE-2005-2005 to obtain users.dat. | Assigned (20050621) | None (candidate not yet proposed) | View | |
6069 | CVE-2002-1685 | Candidate | Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote attackers to execute arbitrary script as other users by injecting script into ext.dll ISAPI. | Assigned (20050621) | None (candidate not yet proposed) | View | |
13237 | CVE-2005-2031 | Candidate | Multiple SQL injection vulnerabilities in socialMPN allow remote attackers to execute arbitrary SQL commands via (1) the sid parameter to article.php, (2) uname parameter to user.php, (3) siteid parameter to viewforum.php, (4) username parameter to newtopic.php, the (5) secid or (6) artid parameter to sections.php, (7) siteid parameter to index.php, or (8) sid parameter to friend.php. | Assigned (20050621) | None (candidate not yet proposed) | View | |
6070 | CVE-2002-1686 | Candidate | Buffer overflow in lscfg of unknown versions of AIX has unknown impact. | Assigned (20050621) | None (candidate not yet proposed) | View |
Page 19248 of 20943, showing 5 records out of 104715 total, starting on record 96236, ending on 96240