CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10253 | CVE-2004-1826 | Candidate | SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10254 | CVE-2004-1827 | Candidate | Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10255 | CVE-2004-1828 | Candidate | Vcard 2.9 and possibly other versions does not require authorization to run uninstall.php, which could allow remote attackers to uninstall Vcard and delete database tables via a direct request to uninstall.php. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10256 | CVE-2004-1829 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in error.php in Gijza.net Error Manager 2.1 for PHP-Nuke 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pagetitle or (2) error parameters, or (3) certain parameters in the error log. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10257 | CVE-2004-1830 | Candidate | error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (1) language, (2) newlang, or (3) lang parameter, which leaks the pathname in a PHP error message. | Assigned (20050504) | None (candidate not yet proposed) | View |
Page 1473 of 20943, showing 5 records out of 104715 total, starting on record 7361, ending on 7365