CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10289  CVE-2004-1862  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Extreme Messageboard (XMB) 1.8 SP3 and 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) xmbuser parameter to xmb.php, (2) folder parameter to u2u.php, (3) viewmost, replymost, or latest parameter to stats.php, (4) message or icons parameter to post.php, (5) threadlist, pagelinks, forumlist, navigation, or (6) forumdisplay parameter to forumdisplay.php.  Assigned (20050504)  None (candidate not yet proposed)    View
7986  CVE-2003-1162  Candidate  index.php in Tritanium Bulletin Board 1.2.3 allows remote attackers to read and reply to arbitrary messages by modifying the thread_id, forum_id, and sid parameters.  Assigned (20050504)  None (candidate not yet proposed)    View
10290  CVE-2004-1863  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allow remote attackers to inject arbitrary web script or HTML via (1) the u2uheader parameter in editprofile.php, the restrict parameter in (2) member.php, (3) misc.php, and (4) today.php, and (5) an arbitrary parameter in phpinfo.php.  Assigned (20050504)  None (candidate not yet proposed)    View
7987  CVE-2003-1163  Candidate  hash.c in Ganglia gmond 2.5.3 allows remote attackers to cause a denial of service (segmentation fault) via a UDP packet that contains a single-byte name string, which is used as an out-of-bounds array index.  Assigned (20050504)  None (candidate not yet proposed)    View
10291  CVE-2004-1864  Candidate  SQL injection vulnerability in Extreme Messageboard (XMB) 1.9 beta allows remote attackers to execute arbitrary SQL commands via the restrict parameter to (1) member.php, (2) misc.php, or (3) today.php.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 1486 of 20943, showing 5 records out of 104715 total, starting on record 7426, ending on 7430

Actions