CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11865  CVE-2005-0659  Candidate  phpBB 2.0.13 and earlier allows remote attackers to obtain sensitive information via a direct request to oracle.php, which reveals the path in a PHP error message.  Assigned (20050307)  None (candidate not yet proposed)    View
11866  CVE-2005-0660  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in D-Forum 1.11 allows remote attackers to inject arbitrary web script or HTML via certain fields, as demonstrated using the page parameter in nav.php3.  Assigned (20050307)  None (candidate not yet proposed)    View
11867  CVE-2005-0661  Candidate  SQL injection vulnerability in the getwbbuserdata function in session.php for Woltlab Burning Board 2.0.3 through 2.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) userid or (2) lastvisit cookie.  Assigned (20050307)  None (candidate not yet proposed)    View
11868  CVE-2005-0662  Candidate  Cross-site scripting (XSS) vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the Avatar field.  Assigned (20050307)  None (candidate not yet proposed)    View
11869  CVE-2005-0663  Candidate  SQL injection vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary SQL commands via the f parameter.  Assigned (20050307)  None (candidate not yet proposed)    View

Page 19673 of 20943, showing 5 records out of 104715 total, starting on record 98361, ending on 98365

Actions