CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8376  CVE-2003-1552  Candidate  Unrestricted file upload vulnerability in uploader.php in Uploader 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/.  Assigned (20080307)  None (candidate not yet proposed)    View
8377  CVE-2003-1553  Candidate  Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password and other user information via a direct request to a user-specific configuration directory.  Assigned (20080326)  None (candidate not yet proposed)    View
8378  CVE-2003-1554  Candidate  Cross-site scripting (XSS) vulnerability in scozbook/add.php in ScozNet ScozBook 1.1 BETA allows remote attackers to inject arbitrary web script or HTML via the (1) username, (2) useremail, (3) aim, (4) msn, (5) sitename and (6) siteaddy variables.  Assigned (20080326)  None (candidate not yet proposed)    View
8379  CVE-2003-1555  Candidate  ScozNet ScozBook 1.1 BETA allows remote attackers to obtain sensitive information via an invalid PG parameter in view.php, which reveals the installation path in an error message.  Assigned (20080326)  None (candidate not yet proposed)    View
8380  CVE-2003-1556  Candidate  Cross-site scripting (XSS) vulnerability in cc_guestbook.pl in CGI City CC GuestBook allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) homepage_title (webpage title) parameters.  Assigned (20080403)  None (candidate not yet proposed)    View

Page 1676 of 20943, showing 5 records out of 104715 total, starting on record 8376, ending on 8380

Actions