CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11508 | CVE-2005-0302 | Candidate | SQL injection vulnerability in default.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to execute arbitrary SQL commands via the referer field in the HTTP header. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11509 | CVE-2005-0303 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_supportError.asp or (2) comersus_backofficelite_supportError.asp in BackOffice Lite 6.0 and 6.01 allow remote attackers to inject arbitrary web script or HTML via the error parameter. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11510 | CVE-2005-0304 | Candidate | Directory traversal vulnerability in DivX Player 2.6 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a filename in a ZIP file for a skin. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11511 | CVE-2005-0305 | Candidate | CRLF injection vulnerability in users.php in Siteman 1.1.10 and earlier allows remote attackers to add arbitrary users and gain privileges via the line parameter in a docreate operation. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11512 | CVE-2005-0306 | Candidate | MercuryBoard 1.1.1 allows remote attackers to gain sensitive information via an HTTP request with the n parameter set to 0, which causes a divide-by-zero error and reveals the path in the resulting error message. | Assigned (20050210) | None (candidate not yet proposed) | View |
Page 19828 of 20943, showing 5 records out of 104715 total, starting on record 99136, ending on 99140