CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12582 | CVE-2005-1376 | Candidate | Multiple directory traversal vulnerabilities in (1) document.php or (2) insertMyDoc.php in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote project administrators to upload arbitrary files. | Assigned (20050502) | None (candidate not yet proposed) | View | |
12583 | CVE-2005-1377 | Candidate | Multiple PHP remote file inclusion vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arbitrary PHP code via unknown vectors. | Assigned (20050502) | None (candidate not yet proposed) | View | |
12584 | CVE-2005-1378 | Candidate | SQL injection vulnerability in posting_notes.php in the notes module for phpBB allows remote attackers to execute arbitrary SQL commands via the p parameter, which is used in the $post_id variable, and other attack vectors. | Assigned (20050502) | None (candidate not yet proposed) | View | |
12585 | CVE-2005-1379 | Candidate | The LAM runtime environment package (lam-runtime-7.0.6-2mdk) on Mandrake Linux installs the mpi user without a password, which allows local users to gain privileges. | Assigned (20050502) | None (candidate not yet proposed) | View | |
12586 | CVE-2005-1380 | Candidate | Cross-site scripting (XSS) vulnerability in BEA Admin Console 8.1 allows remote attackers to execute arbitrary web script or HTML via the server parameter to a JndiFramesetAction action. | Assigned (20050502) | None (candidate not yet proposed) | View |
Page 19488 of 20943, showing 5 records out of 104715 total, starting on record 97436, ending on 97440