CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11498  CVE-2005-0292  Candidate  Multiple SQL injection vulnerabilities in index.php in PHP Gift Registry (phpGiftReg) 1.4.0, and possibly other versions before 1.5.0b1, allow remote attackers to execute arbitrary SQL commands via the (1) messageid, (2) shopper, (3) shopfor, or (4) itemid parameters.  Assigned (20050210)  None (candidate not yet proposed)    View
11499  CVE-2005-0293  Candidate  Directory traversal vulnerability in minis.php in Minis 0.2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the month parameter.  Assigned (20050210)  None (candidate not yet proposed)    View
11500  CVE-2005-0294  Candidate  minis.php in Minis 0.2.1 allows remote attackers to cause a denial of service (infinite loop) via an HTTP request for a file that the web server does not have permission to read, as demonstrated using the month parameter.  Assigned (20050210)  None (candidate not yet proposed)    View
11501  CVE-2005-0295  Candidate  npptnt2.sys in nProtect Gameguard provides unrestricted I/O to any process that calls it, which allows local users to gain privileges.  Assigned (20050210)  None (candidate not yet proposed)    View
11502  CVE-2005-0296  Candidate  ** DISPUTED ** NOTE: this issue has been disputed by the vendor. The error module in Novell GroupWise WebAccess allows remote attackers who have not authenticated to read potentially sensitive information, such as the version, via an incorrect login and a modified (1) error or (2) modify parameter that returns template files or the "about" information page. NOTE: the vendor has disputed this issue.  Assigned (20050210)  None (candidate not yet proposed)    View

Page 19826 of 20943, showing 5 records out of 104715 total, starting on record 99126, ending on 99130

Actions