CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8036 | CVE-2003-1212 | Candidate | MaxWebPortal 1.30 allows remote attackers to perform unauthorized actions by modifying hidden form fields, such as the (1) news, (2) lock, or (3) allmem fields in the "start new topic" HTML page. | Assigned (20050519) | None (candidate not yet proposed) | View | |
8037 | CVE-2003-1213 | Candidate | The default installation of MaxWebPortal 1.30 stores the portal database under the web document root with insecure access control, which allows remote attackers to obtain sensitive information via a direct request to database/db2000.mdb. | Assigned (20050519) | None (candidate not yet proposed) | View | |
8038 | CVE-2003-1214 | Candidate | Unknown vulnerability in the server login for VisualShapers ezContents 2.02 and earlier allows remote attackers to bypass access restrictions and gain access to restricted functions. | Assigned (20050519) | None (candidate not yet proposed) | View | |
6046 | CVE-2002-1662 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Mambo Site Server 4.0.11 allow remote attackers to execute arbitrary script on other clients via (1) search.php and (2) the "Your name" field during account registration. | Assigned (20050519) | None (candidate not yet proposed) | View | |
6047 | CVE-2002-1663 | Candidate | The Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of service (crash) via a POST request with an invalid or missing Content-Length header value. | Assigned (20050519) | None (candidate not yet proposed) | View |
Page 1594 of 20943, showing 5 records out of 104715 total, starting on record 7966, ending on 7970