CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8766  CVE-2004-0338  Candidate  SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter.  Proposed (20040318)  ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall    View
8767  CVE-2004-0339  Candidate  Cross-site scripting (XSS) vulnerability in ViewTopic.php in phpBB, possibly 2.0.6c and earlier, allows remote attackers to execute arbitrary script or HTML as other users via the postorder parameter.  Proposed (20040318)  ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall    View
8771  CVE-2004-0343  Candidate  Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php.  Proposed (20040318)  ACCEPT(3) Armstrong, Cole, Stracener | NOOP(3) Balinsky, Cox, Wall | REVIEWING(1) Green    View
8772  CVE-2004-0344  Candidate  Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via a .. (dot dot) in the attachOld parameter.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8773  CVE-2004-0345  Candidate  Buffer overflow in Red Faction client 1.20 and earlier allows remote servers to execute arbitrary code via a long server name.  Proposed (20040318)  ACCEPT(1) Stracener | NOOP(4) Armstrong, Cole, Cox, Wall    View

Page 10 of 20943, showing 5 records out of 104715 total, starting on record 46, ending on 50

<<first 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 last>>

Actions