CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12622 | CVE-2005-1416 | Candidate | Directory traversal vulnerability in 04WebServer 1.81 allows remote attackers to read files outside of the web root but within the installation folder. | Assigned (20050503) | None (candidate not yet proposed) | View | |
12623 | CVE-2005-1417 | Candidate | Multiple SQL injection vulnerabilities in MaxWebPortal 2.x, 1.35, and other versions allow remote attackers to execute arbitrary SQL commands via (1) article_popular.asp, (2) arguments to dl_popular.asp, (3) arguments to links_popular.asp, (4) arguments to pic_popular.asp, (5) article_rate.asp, (6) dl_rate.asp, (7) links_rate.asp, (8) pic_rates.asp, (9) article_toprated.asp, (10) dl_toprated.asp, (11) links_toprated.asp, (12) arguments to pic_toprated.asp, or (13) the TOPIC_ID or Forum_ID parameters to custom_link.asp. | Assigned (20050503) | None (candidate not yet proposed) | View | |
12624 | CVE-2005-1418 | Candidate | NetLeaf Limited NotJustBrowsing 1.0.3 stores the View Lock Password in plaintext in the notjustbrowsing.prf file, which allows local users to gain privileges. | Assigned (20050503) | None (candidate not yet proposed) | View | |
12625 | CVE-2005-1419 | Candidate | SQL injection vulnerability in the admin login panel for Ocean12 Mailing List Manager 1.06 allows remote attackers to execute arbitrary SQL commands via the Admin_id parameter. | Assigned (20050503) | None (candidate not yet proposed) | View | |
12626 | CVE-2005-1420 | Candidate | Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to determine the full pathname of the server via a request for an invalid page, as demonstrated using "%20" (hex-encoded space). | Assigned (20050503) | None (candidate not yet proposed) | View |
Page 19478 of 20943, showing 5 records out of 104715 total, starting on record 97386, ending on 97390