CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11498 | CVE-2005-0292 | Candidate | Multiple SQL injection vulnerabilities in index.php in PHP Gift Registry (phpGiftReg) 1.4.0, and possibly other versions before 1.5.0b1, allow remote attackers to execute arbitrary SQL commands via the (1) messageid, (2) shopper, (3) shopfor, or (4) itemid parameters. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11499 | CVE-2005-0293 | Candidate | Directory traversal vulnerability in minis.php in Minis 0.2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the month parameter. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11500 | CVE-2005-0294 | Candidate | minis.php in Minis 0.2.1 allows remote attackers to cause a denial of service (infinite loop) via an HTTP request for a file that the web server does not have permission to read, as demonstrated using the month parameter. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11501 | CVE-2005-0295 | Candidate | npptnt2.sys in nProtect Gameguard provides unrestricted I/O to any process that calls it, which allows local users to gain privileges. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11502 | CVE-2005-0296 | Candidate | ** DISPUTED ** NOTE: this issue has been disputed by the vendor. The error module in Novell GroupWise WebAccess allows remote attackers who have not authenticated to read potentially sensitive information, such as the version, via an incorrect login and a modified (1) error or (2) modify parameter that returns template files or the "about" information page. NOTE: the vendor has disputed this issue. | Assigned (20050210) | None (candidate not yet proposed) | View |
Page 19826 of 20943, showing 5 records out of 104715 total, starting on record 99126, ending on 99130