CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10378  CVE-2004-1952  Candidate  SQL injection vulnerability in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password.  Assigned (20050504)  None (candidate not yet proposed)    View
10379  CVE-2004-1953  Candidate  phProfession 2.5 allows remote attackers to gain sensitive information via a direct HTTP request to upload.php, which reveals the path in a PHP error message.  Assigned (20050504)  None (candidate not yet proposed)    View
10380  CVE-2004-1954  Candidate  Cross-site scripting (XSS) vulnerability in modules.php in phProfession 2.5 allows remote attackers to inject arbitrary web script or HTML via the jcode parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10381  CVE-2004-1955  Candidate  SQL injection vulnerability in modules.php in phProfession 2.5 allows remote attackers to execute arbitrary SQL code via the offset parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10382  CVE-2004-1956  Candidate  PostNuke 0.7.2.6 allows remote attackers to gain information via a direct HTTP request to files in the (1) includes/blocks directory, (2) pnadodb directory, (3) NS-NewUser module, (4) NS-Your_Account, (5) NS-LostPassword module, or (6) NS-User module which reveals the path to the web server in a PHP error message.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 1512 of 20943, showing 5 records out of 104715 total, starting on record 7556, ending on 7560

Actions