CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10353  CVE-2004-1926  Candidate  Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4) Displayed time zone fields in a User Profile, or the (5) Name, (6) Description, (7) URL, or (8) Country fields in a Directory/Add Site operation.  Assigned (20050504)  None (candidate not yet proposed)    View
10354  CVE-2004-1927  Candidate  Directory traversal vulnerability in the map feature (tiki-map.phtml) in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to determine the existence of arbitrary files via .. (dot dot) sequences in the mapfile parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10355  CVE-2004-1928  Candidate  The image upload feature in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to upload and possibly execute arbitrary files via the img/wiki_up URL.  Assigned (20050504)  None (candidate not yet proposed)    View
10356  CVE-2004-1929  Candidate  SQL injection vulnerability in the bblogin function in functions.php in PHP-Nuke 6.x through 7.2 allows remote attackers to bypass authentication and gain access by injecting base64-encoded SQL code into the user parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10357  CVE-2004-1930  Candidate  Cross-site scripting (XSS) vulnerability in the cookiedecode function in mainfile.php for PHP-Nuke 6.x through 7.2, when themes are used, allows remote attackers to inject arbitrary web script or HTML via a base64-encoded user parameter or cookie.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 1507 of 20943, showing 5 records out of 104715 total, starting on record 7531, ending on 7535

Actions