CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13153 | CVE-2005-1947 | Candidate | Cross-site request forgery (CSRF) vulnerability in Invision Gallery before 1.3.1 allows remote attackers to delete albums and images as another user via a link or IMG tag to the (1) albums or (2) delimg actions. | Assigned (20050614) | None (candidate not yet proposed) | View | |
13154 | CVE-2005-1948 | Candidate | Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo. | Assigned (20050614) | None (candidate not yet proposed) | View | |
13155 | CVE-2005-1949 | Candidate | The eping_validaddr function in functions.php for the ePing plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacters after a valid argument to the eping_host parameter. | Assigned (20050614) | None (candidate not yet proposed) | View | |
13156 | CVE-2005-1950 | Candidate | hints.pl in Webhints 1.03 allows remote attackers to execute arbitrary commands via shell metacharacters in the argument. | Assigned (20050614) | None (candidate not yet proposed) | View | |
13157 | CVE-2005-1951 | Candidate | Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences in the (1) products_id or (2) pid parameter to index.php or (3) goto parameter to banner.php. | Assigned (20050614) | None (candidate not yet proposed) | View |
Page 19281 of 20943, showing 5 records out of 104715 total, starting on record 96401, ending on 96405