CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12582  CVE-2005-1376  Candidate  Multiple directory traversal vulnerabilities in (1) document.php or (2) insertMyDoc.php in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote project administrators to upload arbitrary files.  Assigned (20050502)  None (candidate not yet proposed)    View
12583  CVE-2005-1377  Candidate  Multiple PHP remote file inclusion vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arbitrary PHP code via unknown vectors.  Assigned (20050502)  None (candidate not yet proposed)    View
12584  CVE-2005-1378  Candidate  SQL injection vulnerability in posting_notes.php in the notes module for phpBB allows remote attackers to execute arbitrary SQL commands via the p parameter, which is used in the $post_id variable, and other attack vectors.  Assigned (20050502)  None (candidate not yet proposed)    View
12585  CVE-2005-1379  Candidate  The LAM runtime environment package (lam-runtime-7.0.6-2mdk) on Mandrake Linux installs the mpi user without a password, which allows local users to gain privileges.  Assigned (20050502)  None (candidate not yet proposed)    View
12586  CVE-2005-1380  Candidate  Cross-site scripting (XSS) vulnerability in BEA Admin Console 8.1 allows remote attackers to execute arbitrary web script or HTML via the server parameter to a JndiFramesetAction action.  Assigned (20050502)  None (candidate not yet proposed)    View

Page 19488 of 20943, showing 5 records out of 104715 total, starting on record 97436, ending on 97440

Actions