CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12844 | CVE-2005-1638 | Candidate | The _writeAttrs function in SafeHTML before 1.3.2 does not properly handle quotes in attribute values, which could allow remote attackers to exploit cross-site scripting (XSS) vulnerabilities in applications that rely on SafeHTML for protection. | Assigned (20050517) | None (candidate not yet proposed) | View | |
12845 | CVE-2005-1639 | Candidate | SQL injection vulnerability in Sigmaweb.DLL in Sigma ISP Manager 6.6 allows remote attackers to execute arbitrary SQL commands via the (1) username, (2) password, or (3) domain fields. | Assigned (20050517) | None (candidate not yet proposed) | View | |
12846 | CVE-2005-1640 | Candidate | mod_channel.bas in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not properly verify whether a host has the owner privileges required to delete IRC channel access entries, which allows remote attackers to bypass intended restrictions. | Assigned (20050517) | None (candidate not yet proposed) | View | |
12847 | CVE-2005-1641 | Candidate | mod_channel in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not allow protected operators to access channels that have been locked out by a key, which allows IRC users to cause a denial of service. | Assigned (20050517) | None (candidate not yet proposed) | View | |
12848 | CVE-2005-1642 | Candidate | SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attackers to execute arbitrary SQL commands via the $email variable. | Assigned (20050517) | None (candidate not yet proposed) | View |
Page 19366 of 20943, showing 5 records out of 104715 total, starting on record 96826, ending on 96830