CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13158  CVE-2005-1952  Candidate  Directory traversal vulnerability in Pico Server (pServ) 3.3 allows remote attackers to read arbitrary files and execute arbitrary commands via a /./ (slash dot slash) before each .. (dot dot) sequence in the URL, which results in an incorrect directory depth count.  Assigned (20050614)  None (candidate not yet proposed)    View
13159  CVE-2005-1953  Candidate  Heap-based buffer overflow in the CGI extension for Pico Server (pServ) 3.3 allows remote attackers to execute arbitrary code via a long HTTP request.  Assigned (20050614)  None (candidate not yet proposed)    View
13160  CVE-2005-1954  Candidate  singapore 0.9.11 allows remote attackers to obtain sensitive information via a direct request to (1) admin.class.php, (2) any .tpl.php file in templates/admin_default/, or (3) any .tpl.php file in templates/default/, which reveal the path in an error message.  Assigned (20050614)  None (candidate not yet proposed)    View
13161  CVE-2005-1955  Candidate  Cross-site scripting (XSS) vulnerability in index.php in singapore 0.9.11 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter.  Assigned (20050614)  None (candidate not yet proposed)    View
13162  CVE-2005-1956  Candidate  File Upload Manager allows remote attackers to upload arbitrary files by modifying the test variable to contain a value of "~~~~~~" (six tildes), which bypasses the file extension checks.  Assigned (20050614)  None (candidate not yet proposed)    View

Page 19282 of 20943, showing 5 records out of 104715 total, starting on record 96406, ending on 96410

Actions