CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12133  CVE-2005-0927  Candidate  Unknown vulnerability in subs.pl for WebAPP 0.9.9 through 0.9.9.2 has unknown impact and attack vectors, probably involving shell metacharacters or .. sequences.  Assigned (20050329)  None (candidate not yet proposed)    View
12134  CVE-2005-0928  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 5.x allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) password, (3) ppuser, (4) sort, or (5) si parameters to showgallery.php, the (6) ppuser, (7) sort, or (8) si parameters to showmembers.php, or (9) the photo parameter to slideshow.php.  Assigned (20050329)  None (candidate not yet proposed)    View
12135  CVE-2005-0929  Candidate  SQL injection vulnerability in PhotoPost PHP Pro 5.x may allow remote attackers to execute arbitrary SQL commands via (1) the sl parameter to showmembers.php or (2) the photo parameter to showphoto.php.  Assigned (20050329)  None (candidate not yet proposed)    View
6035  CVE-2002-1651  Candidate  Cross-site scripting (XSS) vulnerability in Verity Search97 allows remote attackers to insert arbitrary web content and steal sensitive information from other clients, possibly due to certain error messages from template pages that use the (1) vformat or (2) vfilter functions.  Assigned (20050329)  None (candidate not yet proposed)    View
6036  CVE-2002-1652  Candidate  Buffer overflow in cgicso.c for cgiemail 1.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long query parameter.  Assigned (20050329)  None (candidate not yet proposed)    View

Page 19600 of 20943, showing 5 records out of 104715 total, starting on record 97996, ending on 98000

Actions