CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12622  CVE-2005-1416  Candidate  Directory traversal vulnerability in 04WebServer 1.81 allows remote attackers to read files outside of the web root but within the installation folder.  Assigned (20050503)  None (candidate not yet proposed)    View
12623  CVE-2005-1417  Candidate  Multiple SQL injection vulnerabilities in MaxWebPortal 2.x, 1.35, and other versions allow remote attackers to execute arbitrary SQL commands via (1) article_popular.asp, (2) arguments to dl_popular.asp, (3) arguments to links_popular.asp, (4) arguments to pic_popular.asp, (5) article_rate.asp, (6) dl_rate.asp, (7) links_rate.asp, (8) pic_rates.asp, (9) article_toprated.asp, (10) dl_toprated.asp, (11) links_toprated.asp, (12) arguments to pic_toprated.asp, or (13) the TOPIC_ID or Forum_ID parameters to custom_link.asp.  Assigned (20050503)  None (candidate not yet proposed)    View
12624  CVE-2005-1418  Candidate  NetLeaf Limited NotJustBrowsing 1.0.3 stores the View Lock Password in plaintext in the notjustbrowsing.prf file, which allows local users to gain privileges.  Assigned (20050503)  None (candidate not yet proposed)    View
12625  CVE-2005-1419  Candidate  SQL injection vulnerability in the admin login panel for Ocean12 Mailing List Manager 1.06 allows remote attackers to execute arbitrary SQL commands via the Admin_id parameter.  Assigned (20050503)  None (candidate not yet proposed)    View
12626  CVE-2005-1420  Candidate  Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to determine the full pathname of the server via a request for an invalid page, as demonstrated using "%20" (hex-encoded space).  Assigned (20050503)  None (candidate not yet proposed)    View

Page 19478 of 20943, showing 5 records out of 104715 total, starting on record 97386, ending on 97390

Actions