CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12229  CVE-2005-1023  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x to 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) min parameter to the Search module, (2) the categories parameter to the FAQ module, or (3) the ltr parameter to the Encyclopedia module. NOTE: the bid parameter issue in banners.php is already an item in CVE-2005-1000.  Assigned (20050410)  None (candidate not yet proposed)    View
12230  CVE-2005-1024  Candidate  modules.php in PHP-Nuke 6.x to 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) my_headlines, (2) userinfo, or (3) search, which reveals the path in a PHP error message.  Assigned (20050410)  None (candidate not yet proposed)    View
12231  CVE-2005-1025  Candidate  The FTP server in AS/400 4.3, when running in IFS mode, allows remote attackers to obtain sensitive information via a symlink attack using RCMD and the ADDLNK utility, as demonstrated using the QSYS.LIB library.  Assigned (20050410)  None (candidate not yet proposed)    View
12232  CVE-2005-1026  Candidate  Multiple SQL injection vulnerabilities in SnailSource phpBB 2.0.x mods allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to dlman.php in DLMan Pro or (2) id parameter to links.php in Linkz Pro (aka LinksLinks Pro).  Assigned (20050410)  None (candidate not yet proposed)    View
12233  CVE-2005-1027  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x through 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter in the Your_Account module, (2) avatarcategory parameter in the Your_Account module, or (3) lid parameter in the Downloads module.  Assigned (20050410)  None (candidate not yet proposed)    View

Page 19572 of 20943, showing 5 records out of 104715 total, starting on record 97856, ending on 97860

Actions