CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8311  CVE-2003-1487  Candidate  Multiple "command injection" vulnerabilities in Phorum 3.4 through 3.4.2 allow remote attackers to execute arbitrary commands and modify the Phorum configuration files via the (1) UserAdmin program, (2) Edit user profile, or (3) stats program.  Assigned (20071024)  None (candidate not yet proposed)    View
8312  CVE-2003-1488  Candidate  The (1) verif_admin.php and (2) check_admin.php scripts in Truegalerie 1.0 allow remote attackers to gain administrator access via a request to admin.php without the connect parameter and with the loggedin parameter set to any value, such as 1.  Assigned (20071024)  None (candidate not yet proposed)    View
8313  CVE-2003-1489  Candidate  upload.php in Truegalerie 1.0 allows remote attackers to read arbitrary files by specifying the target filename in the file cookie in form.php, then downloading the file from the image gallery.  Assigned (20071024)  None (candidate not yet proposed)    View
8314  CVE-2003-1490  Candidate  SonicWall Pro running firmware 6.4.0.1 allows remote attackers to cause a denial of service (device reset) via a long HTTP POST to the internal interface, possibly due to a buffer overflow.  Assigned (20071024)  None (candidate not yet proposed)    View
8315  CVE-2003-1491  Candidate  Kerio Personal Firewall (KPF) 2.1.4 has a default rule to accept incoming packets from DNS (UDP port 53), which allows remote attackers to bypass the firewall filters via packets with a source port of 53.  Assigned (20071024)  None (candidate not yet proposed)    View

Page 1663 of 20943, showing 5 records out of 104715 total, starting on record 8311, ending on 8315

Actions