CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13214  CVE-2005-2008  Candidate  Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trailing %00 (null).  Assigned (20050620)  None (candidate not yet proposed)    View
13215  CVE-2005-2009  Candidate  Multiple SQL injection vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) ci, (2) d, or (3) m parameter to index.asp, or the (4) bi parameter to blog_comment.asp.  Assigned (20050620)  None (candidate not yet proposed)    View
13216  CVE-2005-2010  Candidate  Cross-site scripting (XSS) vulnerability in trackback.asp in Ublog Reload 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the btitle parameter.  Assigned (20050620)  None (candidate not yet proposed)    View
13217  CVE-2005-2011  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in paFAQ 1.0 Beta 4 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the id parameter in a Question action.  Assigned (20050620)  None (candidate not yet proposed)    View
13218  CVE-2005-2012  Candidate  Multiple SQL injection vulnerabilities in login in paFAQ 1.0 Beta 4 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) id parameters.  Assigned (20050620)  None (candidate not yet proposed)    View

Page 19275 of 20943, showing 5 records out of 104715 total, starting on record 96371, ending on 96375

Actions