CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11986  CVE-2005-0780  Candidate  paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3) category.php, (4) file.php, (5) team.php, (6) license.php, (7) custom.php, (8) admins.php, or (9) backupdb.php, which reveal the path in a PHP error message.  Assigned (20050320)  None (candidate not yet proposed)    View
11987  CVE-2005-0781  Candidate  SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter to pafiledb.php.  Assigned (20050320)  None (candidate not yet proposed)    View
11988  CVE-2005-0782  Candidate  Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the start parameter to pafiledb.php.  Assigned (20050320)  None (candidate not yet proposed)    View
11989  CVE-2005-0783  Candidate  Cross-site scripting (XSS) vulnerability in Phorum before 5.0.14a allows remote attackers to inject arbitrary web script or HTML via the filename of an attached file.  Assigned (20050320)  None (candidate not yet proposed)    View
11990  CVE-2005-0784  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Phorum before 5.0.15 allow remote attackers to inject arbitrary web script or HTML via (1) the subject line to follow.php or (2) the subject line in the user"s personal control panel.  Assigned (20050320)  None (candidate not yet proposed)    View

Page 19631 of 20943, showing 5 records out of 104715 total, starting on record 98151, ending on 98155

Actions