CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12152  CVE-2005-0946  Candidate  SQL injection vulnerability in phpCoin 1.2.1b and earlier allows remote attackers to execute arbitrary SQL commands via the (1) term/keywords field on the search page, (2) username or (3) e-mail field on the forgot password page, or (4) domain name on the ordering new package page.  Assigned (20050403)  None (candidate not yet proposed)    View
12153  CVE-2005-0947  Candidate  Directory traversal vulnerability in auxpage.php in phpCoin 1.2.1b and earlier allows remote attackers to read and execute arbitrary files via a .. (dot dot) in the page parameter.  Assigned (20050403)  None (candidate not yet proposed)    View
12154  CVE-2005-0948  Candidate  SQL injection vulnerability in ad_click.asp for PortalApp allows remote attackers to execute arbitrary SQL commands via the banner_id parameter.  Assigned (20050403)  None (candidate not yet proposed)    View
12155  CVE-2005-0949  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in content.asp in Iatek PortalApp allow remote attackers to inject arbitrary web script or HTML via the (1) contenttype or (2) keywords parameter.  Assigned (20050403)  None (candidate not yet proposed)    View
12156  CVE-2005-0950  Candidate  Directory traversal vulnerability in FastStone 4in1 Browser 1.2 allows remote attackers to read arbitrary files via a (1) ... (triple dot) or (2) .. (dot dot backslash) in the URL.  Assigned (20050403)  None (candidate not yet proposed)    View

Page 19587 of 20943, showing 5 records out of 104715 total, starting on record 97931, ending on 97935

Actions