CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12760  CVE-2005-1554  Candidate  SQL injection vulnerability in view_user.php in WowBB 1.6, 1.61, and 1.62 allows remote attackers to execute arbitrary SQL commands via the sort_by parameter.  Assigned (20050514)  REVIEWING(1) Christey  Christey> The view_user.php/sort_by vector is covered by several CVEs. | Need to figure out how to handle this.  View
12761  CVE-2005-1555  Candidate  Cross-site scripting (XSS) vulnerability in the JRun Web Server in ColdFusion MX 7.0 allows remote attackers to inject arbitrary script or HTML via the URL, which is not properly quoted in the resulting default 404 error page.  Assigned (20050514)  None (candidate not yet proposed)    View
12762  CVE-2005-1556  Candidate  Gamespy cd-key validation system allows remote attackers to cause a denial of service (cd-key already in use) by capturing and replaying a cd-key authorization session.  Assigned (20050514)  None (candidate not yet proposed)    View
12763  CVE-2005-1557  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in WebApp Guestbook PRO 3.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message.  Assigned (20050514)  None (candidate not yet proposed)    View
12764  CVE-2005-1558  Candidate  The web module in Neteyes Nexusway allows remote attackers to bypass authentication and gain administrator privileges by setting the cyclone500_auth cookie.  Assigned (20050514)  None (candidate not yet proposed)    View

Page 19379 of 20943, showing 5 records out of 104715 total, starting on record 96891, ending on 96895

Actions