CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13148 | CVE-2005-1942 | Candidate | Cisco switches that support 802.1x security allow remote attackers to bypass port security and gain access to the VLAN via spoofed Cisco Discovery Protocol (CDP) messages. | Assigned (20050614) | None (candidate not yet proposed) | View | |
13149 | CVE-2005-1943 | Candidate | Multiple SQL injection vulnerabilities in Loki download manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) password field to default.asp or (2) cat parameter to catinfo.asp. | Assigned (20050614) | None (candidate not yet proposed) | View | |
13150 | CVE-2005-1944 | Candidate | xmysqladmin 1.0 and earlier allows local users to delete arbitrary files via a symlink attack on a database backup file in /tmp. | Assigned (20050614) | None (candidate not yet proposed) | View | |
13151 | CVE-2005-1945 | Candidate | Cross-site scripting (XSS) vulnerability in the convert_highlite_words function in Invision Blog before 1.1.2 Final allows remote attackers to inject arbitrary web script or HTML via double hex encoded highlight data. | Assigned (20050614) | None (candidate not yet proposed) | View | |
13152 | CVE-2005-1946 | Candidate | Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to an editentry, replyentry, or editcomment action, or (2) the mid parameter to an aboutme action. | Assigned (20050614) | None (candidate not yet proposed) | View |
Page 19280 of 20943, showing 5 records out of 104715 total, starting on record 96396, ending on 96400