CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10393 | CVE-2004-1967 | Candidate | Cross-site request forgery (CSRF) vulnerabilities in (1) cp_forums.php, (2) cp_usergroup.php, (3) cp_ipbans.php, (4) myhome.php, (5) post.php, or (6) moderator.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allow remote attackers to execute arbitrary code by including the code in an image tag or a link. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10394 | CVE-2004-1968 | Candidate | The readmsg action in myhome.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to read arbitrary messages by modifying the id parameter. | Assigned (20050504) | None (candidate not yet proposed) | View | |
6043 | CVE-2002-1659 | Candidate | user_profile.asp in PortalApp 2.2 allows local users to gain privileges by modifying the user_id variable. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10395 | CVE-2004-1969 | Candidate | The avatar upload capability in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to execute arbitrary script by uploading files that include scripting code such as Javascript. | Assigned (20050504) | None (candidate not yet proposed) | View | |
6044 | CVE-2002-1660 | Candidate | calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter. | Assigned (20050504) | None (candidate not yet proposed) | View |
Page 1515 of 20943, showing 5 records out of 104715 total, starting on record 7571, ending on 7575