CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12006  CVE-2005-0800  Candidate  PHP remote file inclusion vulnerability in install.php in mcNews 1.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the l parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2005-0720.  Assigned (20050320)  None (candidate not yet proposed)    View
12007  CVE-2005-0801  Candidate  Directory traversal vulnerability in includer.cgi in The Includer allows remote attackers to read arbitrary files via (1) a .. (dot dot) or (2) a full pathname in the URL.  Assigned (20050320)  None (candidate not yet proposed)    View
12008  CVE-2005-0802  Candidate  Cross-site scripting (XSS) vulnerability in search.asp in ACS Blog 0.8 through 1.1b allows remote attackers to execute arbitrary web script or HTML via the search parameter.  Assigned (20050320)  None (candidate not yet proposed)    View
12009  CVE-2005-0803  Candidate  The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka "Enhanced Metafile Vulnerability."  Assigned (20050320)  None (candidate not yet proposed)    View
12010  CVE-2005-0804  Candidate  Format string vulnerability in MailEnable 1.8 allows remote attackers to cause a denial of service (application crash) via format string specifiers in the mailto field.  Assigned (20050320)  None (candidate not yet proposed)    View

Page 19635 of 20943, showing 5 records out of 104715 total, starting on record 98171, ending on 98175

Actions