CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9980 | CVE-2004-1552 | Candidate | SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the eventid parameter to calendar.asp. | Assigned (20050220) | None (candidate not yet proposed) | View | |
9981 | CVE-2004-1553 | Candidate | SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the cat parameter to album.asp. NOTE: it was later reported that vector 1 affects aspWebAlbum 3.2, and the vector involves the txtUserName parameter in a processlogin action to album.asp, as reachable from the login action. | Assigned (20050220) | None (candidate not yet proposed) | View | |
9982 | CVE-2004-1554 | Candidate | PHP remote file inclusion vulnerability in livre_include.php in @lex Guestbook allows remote attackers to execute arbitrary PHP code by modifying the chem_absolu parameter to reference a URL on a remote web server that contains the code. | Assigned (20050220) | None (candidate not yet proposed) | View | |
9983 | CVE-2004-1555 | Candidate | Multiple SQL injection vulnerabilities in BroadBoard Instant ASP Message Board allow remote attackers to run arbitrary SQL commands via the (1) keywords parameter to search.asp, (2) handle parameter to profile.asp, (3) txtUserHandle parameter to reg2.asp or (4) txtUserEmail parameter to forgot.asp. | Assigned (20050220) | None (candidate not yet proposed) | View | |
11678 | CVE-2005-0472 | Candidate | Gaim before 1.1.3 allows remote attackers to cause a denial of service (infinite loop) via malformed SNAC packets from (1) AIM or (2) ICQ. | Assigned (20050219) | None (candidate not yet proposed) | View |
Page 19753 of 20943, showing 5 records out of 104715 total, starting on record 98761, ending on 98765