CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11422 | CVE-2005-0216 | Candidate | Cross-site scripting (XSS) vulnerability in formmail.php in Woltlab Burning Board Lite 1.0.0, 1.0.1e, and possibly other versions, allows remote attackers to inject arbitrary web sript and HTML via the userid parameter. | Assigned (20050201) | None (candidate not yet proposed) | View | |
11423 | CVE-2005-0217 | Candidate | SQL injection vulnerability in index.php in Invision Community Blog allows remote attackers to execute arbitrary SQL commands via the eid parameter. | Assigned (20050201) | None (candidate not yet proposed) | View | |
9816 | CVE-2004-1388 | Candidate | Format string vulnerability in the gpsd_report function for BerliOS GPD daemon (gpsd, formerly pygps) 1.9.0 through 2.7 allows remote attackers to execute arbitrary code via certain GPS requests containing format string specifiers that are not properly handled in syslog calls. | Assigned (20050131) | None (candidate not yet proposed) | View | |
9817 | CVE-2004-1389 | Candidate | Unknown vulnerability in the Veritas NetBackup Administrative Assistant interface for NetBackup BusinesServer 3.4, 3.4.1, and 4.5, DataCenter 3.4, 3.4.1, and 4.5, Enterprise Server 5.1, and NetBackup Server 5.0 and 5.1, allows attackers to execute arbitrary commands via the bpjava-susvc process, possibly related to the call-back feature. | Assigned (20050131) | None (candidate not yet proposed) | View | |
11400 | CVE-2005-0194 | Candidate | Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings. | Assigned (20050131) | None (candidate not yet proposed) | View |
Page 19850 of 20943, showing 5 records out of 104715 total, starting on record 99246, ending on 99250