CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12256  CVE-2005-1050  Candidate  The modload op in the Reviews module for PostNuke 0.760-RC3 allows remote attackers to obtain sensitive information via an invalid id parameter, which reveals the path in a PHP error message.  Assigned (20050412)  None (candidate not yet proposed)    View
12257  CVE-2005-1051  Candidate  SQL injection vulnerability in profile.php in PunBB 1.2.4 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a change_email action.  Assigned (20050412)  None (candidate not yet proposed)    View
12258  CVE-2005-1052  Candidate  Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated addresses in the From field in an e-mail message, which could allow remote attackers to spoof e-mail addresses.  Assigned (20050412)  None (candidate not yet proposed)    View
12259  CVE-2005-1053  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in orderwiz.php in ModernBill 4.3.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) c_code or (2) aid parameters.  Assigned (20050412)  None (candidate not yet proposed)    View
12260  CVE-2005-1054  Candidate  PHP remote file inclusion vulnerability in news.php in ModernBill 4.3.0 and earlier allows remote attackers to execute arbitrary PHP code by modifying the DIR parameter to reference a URL on a remote web server that contains the code.  Assigned (20050412)  None (candidate not yet proposed)    View

Page 19565 of 20943, showing 5 records out of 104715 total, starting on record 97821, ending on 97825

Actions