CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8311 | CVE-2003-1487 | Candidate | Multiple "command injection" vulnerabilities in Phorum 3.4 through 3.4.2 allow remote attackers to execute arbitrary commands and modify the Phorum configuration files via the (1) UserAdmin program, (2) Edit user profile, or (3) stats program. | Assigned (20071024) | None (candidate not yet proposed) | View | |
8312 | CVE-2003-1488 | Candidate | The (1) verif_admin.php and (2) check_admin.php scripts in Truegalerie 1.0 allow remote attackers to gain administrator access via a request to admin.php without the connect parameter and with the loggedin parameter set to any value, such as 1. | Assigned (20071024) | None (candidate not yet proposed) | View | |
8313 | CVE-2003-1489 | Candidate | upload.php in Truegalerie 1.0 allows remote attackers to read arbitrary files by specifying the target filename in the file cookie in form.php, then downloading the file from the image gallery. | Assigned (20071024) | None (candidate not yet proposed) | View | |
8314 | CVE-2003-1490 | Candidate | SonicWall Pro running firmware 6.4.0.1 allows remote attackers to cause a denial of service (device reset) via a long HTTP POST to the internal interface, possibly due to a buffer overflow. | Assigned (20071024) | None (candidate not yet proposed) | View | |
8315 | CVE-2003-1491 | Candidate | Kerio Personal Firewall (KPF) 2.1.4 has a default rule to accept incoming packets from DNS (UDP port 53), which allows remote attackers to bypass the firewall filters via packets with a source port of 53. | Assigned (20071024) | None (candidate not yet proposed) | View |
Page 1663 of 20943, showing 5 records out of 104715 total, starting on record 8311, ending on 8315