CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6266  CVE-2002-1884  Candidate  index.php in Py-Membres 3.1 allows remote attackers to log in as an administrator by setting the pymembs parameter to "admin".  Assigned (20050629)  None (candidate not yet proposed)    View
6267  CVE-2002-1885  Candidate  PHP remote file inclusion vulnerability in showhits.php3 for PowerPhlogger (PPhlogger) 2.0.9 through 2.2.2 allows remote attackers to execute arbitrary PHP code via the rel_path parameter.  Assigned (20050629)  None (candidate not yet proposed)    View
6268  CVE-2002-1886  Candidate  TightAuction 3.0 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain the database username and password.  Assigned (20050629)  None (candidate not yet proposed)    View
6269  CVE-2002-1887  Candidate  PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute arbitrary PHP code via the l parameter.  Assigned (20050629)  None (candidate not yet proposed)    View
6270  CVE-2002-1888  Candidate  CommonName Toolbar 3.5.2.0 sends unqualified domain name requests to the CommonName organization and possibly other web servers for name resolution, which allows those organizations to obtain internal server names.  Assigned (20050629)  None (candidate not yet proposed)    View

Page 1254 of 20943, showing 5 records out of 104715 total, starting on record 6266, ending on 6270

Actions