CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12891 | CVE-2005-1685 | Candidate | episodex guestbook allows remote attackers to bypass authentication and edit scripts via a direct request to admin.asp. | Assigned (20050520) | None (candidate not yet proposed) | View | |
12892 | CVE-2005-1686 | Candidate | Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename. NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that web browsers and email clients could be configured to provide a file name as an argument to gedit, so there is a valid attack that crosses security boundaries. | Assigned (20050520) | None (candidate not yet proposed) | View | |
12893 | CVE-2005-1687 | Candidate | SQL injection vulnerability in wp-trackback.php in Wordpress 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the tb_id parameter. | Assigned (20050520) | None (candidate not yet proposed) | View | |
12894 | CVE-2005-1688 | Candidate | Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message. | Assigned (20050520) | None (candidate not yet proposed) | View | |
10497 | CVE-2004-2071 | Candidate | Macallan Mail Solution 2.8.4.6 (Build 260), and possibly earlier versions, allows remote attackers to bypass authentication in the web interface via an HTTP GET request with two slashes ("//") after the server name. | Assigned (20050519) | None (candidate not yet proposed) | View |
Page 19349 of 20943, showing 5 records out of 104715 total, starting on record 96741, ending on 96745