CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12577  CVE-2005-1371  Candidate  BPFTPServer service in BulletProof FTP Server 2.4.0.31 does not properly drop privileges before opening files through the Help menu, which allows local users to gain privileges.  Assigned (20050502)  None (candidate not yet proposed)    View
12578  CVE-2005-1372  Candidate  nvstatsmngr.exe process in BakBone NetVault 7.1 does not properly drop privileges before opening files, which allows local users to gain privileges via the Help menu.  Assigned (20050502)  None (candidate not yet proposed)    View
12579  CVE-2005-1373  Candidate  Multiple SQL injection vulnerabilities in index.php in Dream4 Koobi CMS 4.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) q or (2) p parameters.  Assigned (20050502)  None (candidate not yet proposed)    View
12580  CVE-2005-1374  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to inject arbitrary web script or HTML via (1) exercise_result.php, (2) exercice_submit.php, (3) agenda.php, (4) learningPathList.php, (5) learningPathAdmin.php, (6) learningPath.php, (7) userLog.php, (8) tool parameter to toolaccess_details.php, (9) data parameter to user_access_details.php, or (10) coursePath parameter to myagenda.php.  Assigned (20050502)  None (candidate not yet proposed)    View
12581  CVE-2005-1375  Candidate  Multiple SQL injection vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arbitrary SQL commands via (1) learningPath.php, (2) learningPathAdmin.php, (3) learnPath_details.php, (4) modules_pool.php, (5) module.php, (6) uInfo parameter in userInfo.php, or (7) exo_id parameter to exercises_details.php.  Assigned (20050502)  None (candidate not yet proposed)    View

Page 19487 of 20943, showing 5 records out of 104715 total, starting on record 97431, ending on 97435

Actions