CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5291  CVE-2002-0902  Candidate  Cross-site scripting vulnerability in phpBB 2.0.0 (phpBB2) allows remote attackers to execute Javascript as other phpBB users by including a http:// and a double-quote (") in the [IMG] tag, which bypasses phpBB"s security check, terminates the src parameter of the resulting HTML IMG tag, and injects the script.  Proposed (20020830)  ACCEPT(1) Frech | NOOP(6) Alderson, Armstrong, Cole, Cox, Foat, Jones    View
5292  CVE-2002-0903  Candidate  register.php for WoltLab Burning Board (wbboard) 1.1.1 uses a small number of random values for the "code" parameter that is provided to action.php to approve a new registration, along with predictable new user ID"s, which allows remote attackers to hijack new user accounts via a brute force attack on the new user ID and the code value.  Proposed (20020830)  ACCEPT(2) Alderson, Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Jones    View
5293  CVE-2002-0904  Entry  SayText function in Kismet 2.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters (backtick or pipe) in the essid argument.        View
5294  CVE-2002-0905  Candidate  Buffer overflow in sqlexec for Informix SE-7.25 allows local users to gain root privileges via a long INFORMIXDIR environment variable.  Proposed (20020830)  ACCEPT(2) Alderson, Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Jones    View
5295  CVE-2002-0906  Entry  Buffer overflow in Sendmail before 8.12.5, when configured to use a custom DNS map to query TXT records, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malicious DNS server.        View

Page 1059 of 20943, showing 5 records out of 104715 total, starting on record 5291, ending on 5295

Actions