CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12760 | CVE-2005-1554 | Candidate | SQL injection vulnerability in view_user.php in WowBB 1.6, 1.61, and 1.62 allows remote attackers to execute arbitrary SQL commands via the sort_by parameter. | Assigned (20050514) | REVIEWING(1) Christey | Christey> The view_user.php/sort_by vector is covered by several CVEs. | Need to figure out how to handle this. | View |
12761 | CVE-2005-1555 | Candidate | Cross-site scripting (XSS) vulnerability in the JRun Web Server in ColdFusion MX 7.0 allows remote attackers to inject arbitrary script or HTML via the URL, which is not properly quoted in the resulting default 404 error page. | Assigned (20050514) | None (candidate not yet proposed) | View | |
12762 | CVE-2005-1556 | Candidate | Gamespy cd-key validation system allows remote attackers to cause a denial of service (cd-key already in use) by capturing and replaying a cd-key authorization session. | Assigned (20050514) | None (candidate not yet proposed) | View | |
12763 | CVE-2005-1557 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in WebApp Guestbook PRO 3.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message. | Assigned (20050514) | None (candidate not yet proposed) | View | |
12764 | CVE-2005-1558 | Candidate | The web module in Neteyes Nexusway allows remote attackers to bypass authentication and gain administrator privileges by setting the cyclone500_auth cookie. | Assigned (20050514) | None (candidate not yet proposed) | View |
Page 19379 of 20943, showing 5 records out of 104715 total, starting on record 96891, ending on 96895