CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12770  CVE-2005-1564  Candidate  post_bug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to "enter bugs into products that are closed for bug entry" by modifying the URL to specify the name of the product.  Assigned (20050514)  None (candidate not yet proposed)    View
12771  CVE-2005-1565  Candidate  Bugzilla 2.17.1 through 2.18, 2.19.1, and 2.19.2, when a user is prompted to log in while attempting to view a chart, displays the password in the URL, which may allow local users to gain sensitive information from web logs or browser history.  Assigned (20050514)  None (candidate not yet proposed)    View
12772  CVE-2005-1566  Candidate  Acrowave AAP-3100AR wireless router allows remote attackers to bypass authentication by pressing CTRL-C at the username or password prompt in a telnet session, which causes the shell to crash and restart, then leave the user in the new shell.  Assigned (20050514)  None (candidate not yet proposed)    View
12773  CVE-2005-1567  Candidate  SQL injection vulnerability in topic.php in DirectTopics 2.1 and 2.2 allows remote attackers to execute arbitrary SQL commands via the topic parameter.  Assigned (20050514)  None (candidate not yet proposed)    View
12774  CVE-2005-1568  Candidate  topic.php in DirectTopics 2.1 and 2.2 allows remote attackers to obtain sensitive information via an invalid topic parameter, which reveals the path in an error message.  Assigned (20050514)  None (candidate not yet proposed)    View

Page 19381 of 20943, showing 5 records out of 104715 total, starting on record 96901, ending on 96905

Actions