CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12844  CVE-2005-1638  Candidate  The _writeAttrs function in SafeHTML before 1.3.2 does not properly handle quotes in attribute values, which could allow remote attackers to exploit cross-site scripting (XSS) vulnerabilities in applications that rely on SafeHTML for protection.  Assigned (20050517)  None (candidate not yet proposed)    View
12845  CVE-2005-1639  Candidate  SQL injection vulnerability in Sigmaweb.DLL in Sigma ISP Manager 6.6 allows remote attackers to execute arbitrary SQL commands via the (1) username, (2) password, or (3) domain fields.  Assigned (20050517)  None (candidate not yet proposed)    View
12846  CVE-2005-1640  Candidate  mod_channel.bas in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not properly verify whether a host has the owner privileges required to delete IRC channel access entries, which allows remote attackers to bypass intended restrictions.  Assigned (20050517)  None (candidate not yet proposed)    View
12847  CVE-2005-1641  Candidate  mod_channel in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not allow protected operators to access channels that have been locked out by a key, which allows IRC users to cause a denial of service.  Assigned (20050517)  None (candidate not yet proposed)    View
12848  CVE-2005-1642  Candidate  SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attackers to execute arbitrary SQL commands via the $email variable.  Assigned (20050517)  None (candidate not yet proposed)    View

Page 19366 of 20943, showing 5 records out of 104715 total, starting on record 96826, ending on 96830

Actions