CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11617  CVE-2005-0411  Candidate  Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to include arbitrary PHP files via .. (dot dot) sequences in the load parameter.  Assigned (20050214)  None (candidate not yet proposed)    View
11618  CVE-2005-0412  Candidate  Cross-site scripting (XSS) vulnerability in Spidean PostWrap allows remote attackers to inject arbitrary HTML and web script via the page parameter.  Assigned (20050214)  None (candidate not yet proposed)    View
11619  CVE-2005-0413  Candidate  Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) the member parameter in member.php, (3) the email parameter in forgot.php, or (4) the nbuser or nbpass parameters in include.php. NOTE: it was later reported that vector 2 exists in 3.0 and earlier.  Assigned (20050214)  None (candidate not yet proposed)    View
11620  CVE-2005-0414  Candidate  SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands via a reply post action for index.php with (1) the t parameter or (2) the qu parameter.  Assigned (20050214)  None (candidate not yet proposed)    View
11621  CVE-2005-0415  Candidate  Multiple memory leaks in the MQL parser in Emdros before 1.1.22 allow remote attackers to cause a denial of service (memory consumption) via malformed MQL statements.  Assigned (20050214)  None (candidate not yet proposed)    View

Page 19785 of 20943, showing 5 records out of 104715 total, starting on record 98921, ending on 98925

Actions