CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12006 | CVE-2005-0800 | Candidate | PHP remote file inclusion vulnerability in install.php in mcNews 1.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the l parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2005-0720. | Assigned (20050320) | None (candidate not yet proposed) | View | |
12007 | CVE-2005-0801 | Candidate | Directory traversal vulnerability in includer.cgi in The Includer allows remote attackers to read arbitrary files via (1) a .. (dot dot) or (2) a full pathname in the URL. | Assigned (20050320) | None (candidate not yet proposed) | View | |
12008 | CVE-2005-0802 | Candidate | Cross-site scripting (XSS) vulnerability in search.asp in ACS Blog 0.8 through 1.1b allows remote attackers to execute arbitrary web script or HTML via the search parameter. | Assigned (20050320) | None (candidate not yet proposed) | View | |
12009 | CVE-2005-0803 | Candidate | The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka "Enhanced Metafile Vulnerability." | Assigned (20050320) | None (candidate not yet proposed) | View | |
12010 | CVE-2005-0804 | Candidate | Format string vulnerability in MailEnable 1.8 allows remote attackers to cause a denial of service (application crash) via format string specifiers in the mailto field. | Assigned (20050320) | None (candidate not yet proposed) | View |
Page 19635 of 20943, showing 5 records out of 104715 total, starting on record 98171, ending on 98175