CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11865 | CVE-2005-0659 | Candidate | phpBB 2.0.13 and earlier allows remote attackers to obtain sensitive information via a direct request to oracle.php, which reveals the path in a PHP error message. | Assigned (20050307) | None (candidate not yet proposed) | View | |
11866 | CVE-2005-0660 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in D-Forum 1.11 allows remote attackers to inject arbitrary web script or HTML via certain fields, as demonstrated using the page parameter in nav.php3. | Assigned (20050307) | None (candidate not yet proposed) | View | |
11867 | CVE-2005-0661 | Candidate | SQL injection vulnerability in the getwbbuserdata function in session.php for Woltlab Burning Board 2.0.3 through 2.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) userid or (2) lastvisit cookie. | Assigned (20050307) | None (candidate not yet proposed) | View | |
11868 | CVE-2005-0662 | Candidate | Cross-site scripting (XSS) vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the Avatar field. | Assigned (20050307) | None (candidate not yet proposed) | View | |
11869 | CVE-2005-0663 | Candidate | SQL injection vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary SQL commands via the f parameter. | Assigned (20050307) | None (candidate not yet proposed) | View |
Page 19673 of 20943, showing 5 records out of 104715 total, starting on record 98361, ending on 98365