CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13317  CVE-2005-2111  Candidate  login.cgi in Community Link Pro Web Editor allows remote attackers to execute arbitrary commands via the file parameter.  Assigned (20050701)  None (candidate not yet proposed)    View
78853  CVE-2015-1576  Candidate  Multiple SQL injection vulnerabilities in u5CMS before 3.9.4 allow remote attackers to execute arbitrary SQL commands via the name parameter to (1) copy2.php, (2) localize.php, (3) metai.php, (4) nc.php, (5) new2.php, or (6) rename2.php in u5admin/; (7) c parameter to u5admin/editor.php; (8) typ parameter to u5admin/meta2.php; or (9) newname parameter to u5admin/rename2.php.  Assigned (20150211)  None (candidate not yet proposed)    View
13573  CVE-2005-2367  Candidate  Format string vulnerability in the proto_item_set_text function in Ethereal 0.9.4 through 0.10.11, as used in multiple dissectors, allows remote attackers to write to arbitrary memory locations and gain privileges via a crafted AFP packet.  Assigned (20050726)  None (candidate not yet proposed)    View
79109  CVE-2015-1832  Candidate  XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows context-dependent attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving XmlVTI and the XML datatype.  Assigned (20150217)  None (candidate not yet proposed)    View
13829  CVE-2005-2623  Candidate  ECW-Shop 6.0.2 allows remote attackers to reduce the total cost of their shopping cart by specifying a negative quantity for an item, which causes the price of the item to be subtracted from the total cost.  Assigned (20050819)  None (candidate not yet proposed)    View

Page 440 of 20943, showing 5 records out of 104715 total, starting on record 2196, ending on 2200

Actions