CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12136  CVE-2005-0930  Candidate  Cross-site scripting (XSS) vulnerability in message.php in Chatness 2.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the user field or (2) the message parameter to message.php.  Assigned (20050330)  None (candidate not yet proposed)    View
12137  CVE-2005-0931  Candidate  PHP remote file inclusion vulnerability in The Includer 1.0 and 1.1 allows remote attackers to execute arbitrary PHP code.  Assigned (20050330)  None (candidate not yet proposed)    View
12138  CVE-2005-0932  Candidate  Multiple SQL injection vulnerabilities in phpCOIN 1.2.1b and earlier allow remote attackers to execute arbitrary SQL commands (1) via the search engine, (2) the username or email fields in the "forgotten password" feature, or (3) the domain name in a package order.  Assigned (20050330)  None (candidate not yet proposed)    View
12139  CVE-2005-0933  Candidate  Directory traversal vulnerability in auxpage.php for phpCOIN 1.2.1b and earlier allows remote attackers to read arbitrary files via the page parameter.  Assigned (20050330)  None (candidate not yet proposed)    View
12140  CVE-2005-0934  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in WackoWiki R4 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.  Assigned (20050330)  None (candidate not yet proposed)    View

Page 19591 of 20943, showing 5 records out of 104715 total, starting on record 97951, ending on 97955

Actions