CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12765 | CVE-2005-1559 | Candidate | The web module in Neteyes Nexusway allows remote attackers to execute arbitrary commands via hex-encoded shell metacharacters in the ip parameter for (1) nslookup.cgi or (2) ping.cgi. | Assigned (20050514) | None (candidate not yet proposed) | View | |
12766 | CVE-2005-1560 | Candidate | The SSH module in Neteyes Nexusway allows remote attackers to execute arbitrary commands via shell metacharacters in arguments to certain commands, as demonstrated using ping and traceroute. | Assigned (20050514) | None (candidate not yet proposed) | View | |
12767 | CVE-2005-1561 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in post.asp in MaxWebPortal 1.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mod, (2) M, or (3) type parameter. | Assigned (20050514) | None (candidate not yet proposed) | View | |
12768 | CVE-2005-1562 | Candidate | Multiple SQL injection vulnerabilities in MaxWebPortal 1.3.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fpassword parameter to inc_functions.asp, (2) txtAddress, (3) message, or (4) subject parameter to post_info.asp, (5) andor parameter to search.asp, (6) verkey parameter to pop_profile.asp, or (7) Remove or (8) Delete parameter to pm_delete2.asp. | Assigned (20050514) | None (candidate not yet proposed) | View | |
12769 | CVE-2005-1563 | Candidate | Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 displays a different error message depending on whether a product exists or not, which allows remote attackers to determine hidden products. | Assigned (20050514) | None (candidate not yet proposed) | View |
Page 19380 of 20943, showing 5 records out of 104715 total, starting on record 96896, ending on 96900