CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13746  CVE-2005-2540  Candidate  CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII char 13 (carriage return) in the signature field, which is injected into a PHP script without a preceding comment character, which can then be executed by a direct request.  Assigned (20050810)  None (candidate not yet proposed)    View
13747  CVE-2005-2541  Candidate  Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.  Assigned (20050810)  None (candidate not yet proposed)    View
13748  CVE-2005-2542  Candidate  Invision Power Board (IPB) 1.0.3 allows remote attackers to inject arbitrary web script or HTML via an attachment, which is automatically downloaded and processed as HTML.  Assigned (20050810)  None (candidate not yet proposed)    View
13749  CVE-2005-2543  Candidate  Directory traversal vulnerability in wce.download.php in Comdev eCommerce 3.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the download parameter.  Assigned (20050810)  None (candidate not yet proposed)    View
13750  CVE-2005-2544  Candidate  PHP remote file inclusion vulnerability in config.php in Comdev eCommerce 3.0 allows remote attackers to execute arbitrary PHP code via the path[docroot] parameter.  Assigned (20050810)  None (candidate not yet proposed)    View

Page 1925 of 20943, showing 5 records out of 104715 total, starting on record 9621, ending on 9625

Actions