CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10378 | CVE-2004-1952 | Candidate | SQL injection vulnerability in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10379 | CVE-2004-1953 | Candidate | phProfession 2.5 allows remote attackers to gain sensitive information via a direct HTTP request to upload.php, which reveals the path in a PHP error message. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10380 | CVE-2004-1954 | Candidate | Cross-site scripting (XSS) vulnerability in modules.php in phProfession 2.5 allows remote attackers to inject arbitrary web script or HTML via the jcode parameter. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10381 | CVE-2004-1955 | Candidate | SQL injection vulnerability in modules.php in phProfession 2.5 allows remote attackers to execute arbitrary SQL code via the offset parameter. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10382 | CVE-2004-1956 | Candidate | PostNuke 0.7.2.6 allows remote attackers to gain information via a direct HTTP request to files in the (1) includes/blocks directory, (2) pnadodb directory, (3) NS-NewUser module, (4) NS-Your_Account, (5) NS-LostPassword module, or (6) NS-User module which reveals the path to the web server in a PHP error message. | Assigned (20050504) | None (candidate not yet proposed) | View |
Page 1512 of 20943, showing 5 records out of 104715 total, starting on record 7556, ending on 7560