CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12152 | CVE-2005-0946 | Candidate | SQL injection vulnerability in phpCoin 1.2.1b and earlier allows remote attackers to execute arbitrary SQL commands via the (1) term/keywords field on the search page, (2) username or (3) e-mail field on the forgot password page, or (4) domain name on the ordering new package page. | Assigned (20050403) | None (candidate not yet proposed) | View | |
12153 | CVE-2005-0947 | Candidate | Directory traversal vulnerability in auxpage.php in phpCoin 1.2.1b and earlier allows remote attackers to read and execute arbitrary files via a .. (dot dot) in the page parameter. | Assigned (20050403) | None (candidate not yet proposed) | View | |
12154 | CVE-2005-0948 | Candidate | SQL injection vulnerability in ad_click.asp for PortalApp allows remote attackers to execute arbitrary SQL commands via the banner_id parameter. | Assigned (20050403) | None (candidate not yet proposed) | View | |
12155 | CVE-2005-0949 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in content.asp in Iatek PortalApp allow remote attackers to inject arbitrary web script or HTML via the (1) contenttype or (2) keywords parameter. | Assigned (20050403) | None (candidate not yet proposed) | View | |
12156 | CVE-2005-0950 | Candidate | Directory traversal vulnerability in FastStone 4in1 Browser 1.2 allows remote attackers to read arbitrary files via a (1) ... (triple dot) or (2) .. (dot dot backslash) in the URL. | Assigned (20050403) | None (candidate not yet proposed) | View |
Page 19587 of 20943, showing 5 records out of 104715 total, starting on record 97931, ending on 97935