CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8361 | CVE-2003-1537 | Candidate | Directory traversal vulnerability in PostNuke 0.723 and earlier allows remote attackers to include arbitrary files named theme.php via the theme parameter to index.php. | Assigned (20071113) | None (candidate not yet proposed) | View | |
8362 | CVE-2003-1538 | Candidate | susehelp in SuSE Linux 8.1, Enterprise Server 8, Office Server, and Openexchange Server 4 does not properly filter shell metacharacters, which allows remote attackers to execute arbitrary commands via CGI queries. | Assigned (20071220) | None (candidate not yet proposed) | View | |
8363 | CVE-2003-1539 | Candidate | Cross-site scripting (XSS) vulnerability in ONEdotOH Simple File Manager (SFM) before 0.21 allows remote attackers to inject arbitrary web script or HTML via (1) file names and (2) directory names. | Assigned (20080109) | None (candidate not yet proposed) | View | |
8364 | CVE-2003-1540 | Candidate | WF-Chat 1.0 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain authentication information via a direct request to (1) !pwds.txt and (2) !nicks.txt. | Assigned (20080212) | None (candidate not yet proposed) | View | |
8365 | CVE-2003-1541 | Candidate | PlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin script password, and other passwords, via a direct request to files/passwd.txt. | Assigned (20080213) | None (candidate not yet proposed) | View |
Page 1673 of 20943, showing 5 records out of 104715 total, starting on record 8361, ending on 8365