CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11903  CVE-2005-0697  Candidate  SQL injection vulnerability in the process_picture function xp_publish.php in CopperExport 0.2.1 allows remote attackers to execute arbitrary SQL commands, possibly via the (1) title, (2) caption, or (3) keywords parameters.  Assigned (20050309)  None (candidate not yet proposed)    View
11904  CVE-2005-0698  Candidate  PHP remote file inclusion vulnerability in PHPWebLog 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) G_PATH parameter to init.inc.php or the (2) PATH parameter to index.php to reference a URL on a remote web server that contains the code.  Assigned (20050309)  None (candidate not yet proposed)    View
11905  CVE-2005-0699  Candidate  Multiple buffer overflows in the dissect_a11_radius function in the CDMA A11 (3G-A11) dissector (packet-3g-a11.c) for Ethereal 0.10.9 and earlier allow remote attackers to execute arbitrary code via RADIUS authentication packets with large length values.  Assigned (20050309)  None (candidate not yet proposed)    View
11906  CVE-2005-0700  Candidate  The export_index action in myadmin.php for Aztek Forum 4.0 allows remote attackers to obtain database files, possibly by setting the ATK_ADMIN cookie.  Assigned (20050309)  None (candidate not yet proposed)    View
11907  CVE-2005-0701  Candidate  Directory traversal vulnerability in Oracle Database Server 8i and 9i allows remote attackers to read or rename arbitrary files via "\.\.." (modified dot dot backslash) sequences to UTL_FILE functions such as (1) UTL_FILE.FOPEN or (2) UTL_FILE.frename.  Assigned (20050309)  None (candidate not yet proposed)    View

Page 19669 of 20943, showing 5 records out of 104715 total, starting on record 98341, ending on 98345

Actions