CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13153  CVE-2005-1947  Candidate  Cross-site request forgery (CSRF) vulnerability in Invision Gallery before 1.3.1 allows remote attackers to delete albums and images as another user via a link or IMG tag to the (1) albums or (2) delimg actions.  Assigned (20050614)  None (candidate not yet proposed)    View
13154  CVE-2005-1948  Candidate  Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo.  Assigned (20050614)  None (candidate not yet proposed)    View
13155  CVE-2005-1949  Candidate  The eping_validaddr function in functions.php for the ePing plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacters after a valid argument to the eping_host parameter.  Assigned (20050614)  None (candidate not yet proposed)    View
13156  CVE-2005-1950  Candidate  hints.pl in Webhints 1.03 allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.  Assigned (20050614)  None (candidate not yet proposed)    View
13157  CVE-2005-1951  Candidate  Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences in the (1) products_id or (2) pid parameter to index.php or (3) goto parameter to banner.php.  Assigned (20050614)  None (candidate not yet proposed)    View

Page 19281 of 20943, showing 5 records out of 104715 total, starting on record 96401, ending on 96405

Actions