CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8361  CVE-2003-1537  Candidate  Directory traversal vulnerability in PostNuke 0.723 and earlier allows remote attackers to include arbitrary files named theme.php via the theme parameter to index.php.  Assigned (20071113)  None (candidate not yet proposed)    View
8362  CVE-2003-1538  Candidate  susehelp in SuSE Linux 8.1, Enterprise Server 8, Office Server, and Openexchange Server 4 does not properly filter shell metacharacters, which allows remote attackers to execute arbitrary commands via CGI queries.  Assigned (20071220)  None (candidate not yet proposed)    View
8363  CVE-2003-1539  Candidate  Cross-site scripting (XSS) vulnerability in ONEdotOH Simple File Manager (SFM) before 0.21 allows remote attackers to inject arbitrary web script or HTML via (1) file names and (2) directory names.  Assigned (20080109)  None (candidate not yet proposed)    View
8364  CVE-2003-1540  Candidate  WF-Chat 1.0 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain authentication information via a direct request to (1) !pwds.txt and (2) !nicks.txt.  Assigned (20080212)  None (candidate not yet proposed)    View
8365  CVE-2003-1541  Candidate  PlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin script password, and other passwords, via a direct request to files/passwd.txt.  Assigned (20080213)  None (candidate not yet proposed)    View

Page 1673 of 20943, showing 5 records out of 104715 total, starting on record 8361, ending on 8365

Actions