CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13318 | CVE-2005-2112 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) order parameter to edit.php or (2) cid parameter to comment_edit.php. | Assigned (20050701) | None (candidate not yet proposed) | View | |
78854 | CVE-2015-1577 | Candidate | Directory traversal vulnerability in u5admin/deletefile.php in u5CMS before 3.9.4 allows remote attackers to write to arbitrary files via a (1) .. (dot dot) or (2) full pathname in the f parameter. | Assigned (20150211) | None (candidate not yet proposed) | View | |
13574 | CVE-2005-2368 | Candidate | vim 6.3 before 6.3.082, with modelines enabled, allows external user-assisted attackers to execute arbitrary commands via shell metacharacters in the (1) glob or (2) expand commands of a foldexpr expression for calculating fold levels. | Assigned (20050726) | None (candidate not yet proposed) | View | |
79110 | CVE-2015-1833 | Candidate | XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.1, and 2.10.x before 2.10.1 allows remote attackers to read arbitrary files and send requests to intranet servers via a crafted WebDAV request. | Assigned (20150217) | None (candidate not yet proposed) | View | |
13830 | CVE-2005-2624 | Candidate | Eval injection vulnerability in CPAINT 1.3-SP allows remote attackers to execute arbitrary ASP code via the cpaint_argument[] parameter to (1) calculator.asp or (2) cpaintfile.asp, which is directly fed into an eval statement. | Assigned (20050819) | None (candidate not yet proposed) | View |
Page 504 of 20943, showing 5 records out of 104715 total, starting on record 2516, ending on 2520