CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13148  CVE-2005-1942  Candidate  Cisco switches that support 802.1x security allow remote attackers to bypass port security and gain access to the VLAN via spoofed Cisco Discovery Protocol (CDP) messages.  Assigned (20050614)  None (candidate not yet proposed)    View
13149  CVE-2005-1943  Candidate  Multiple SQL injection vulnerabilities in Loki download manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) password field to default.asp or (2) cat parameter to catinfo.asp.  Assigned (20050614)  None (candidate not yet proposed)    View
13150  CVE-2005-1944  Candidate  xmysqladmin 1.0 and earlier allows local users to delete arbitrary files via a symlink attack on a database backup file in /tmp.  Assigned (20050614)  None (candidate not yet proposed)    View
13151  CVE-2005-1945  Candidate  Cross-site scripting (XSS) vulnerability in the convert_highlite_words function in Invision Blog before 1.1.2 Final allows remote attackers to inject arbitrary web script or HTML via double hex encoded highlight data.  Assigned (20050614)  None (candidate not yet proposed)    View
13152  CVE-2005-1946  Candidate  Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to an editentry, replyentry, or editcomment action, or (2) the mid parameter to an aboutme action.  Assigned (20050614)  None (candidate not yet proposed)    View

Page 19280 of 20943, showing 5 records out of 104715 total, starting on record 96396, ending on 96400

Actions