CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6202  CVE-2002-1820  Candidate  register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allows a remote attacker to impersonate the administrator by registering an account name of admin with a lower case "a."  Assigned (20050629)  None (candidate not yet proposed)    View
6203  CVE-2002-1821  Candidate  Ultimate PHP Board (UPB) 1.0 and 1.0b allows remote authenticated users to gain privileges and perform unauthorized actions via direct requests to (1) admin_members.php, (2) admin_config.php, (3) admin_cat.php, or (4) admin_forum.php.  Assigned (20050629)  None (candidate not yet proposed)    View
6204  CVE-2002-1822  Candidate  IBM HTTP Server 1.0 on AS/400 allows remote attackers to obtain the path to the web root directory and other sensitive information, which is leaked in an error mesage when a request is made for a non-existent Java Server Page (JSP).  Assigned (20050629)  None (candidate not yet proposed)    View
6205  CVE-2002-1823  Candidate  Buffer overflow in the HttpGetRequest function in Zeroo HTTP server 1.5 allows remote attackers to execute arbitrary code via a long HTTP request.  Assigned (20050629)  None (candidate not yet proposed)    View
6206  CVE-2002-1824  Candidate  Microsoft Internet Explorer 6.0, when handling an expired CA-CERT in a webserver"s certificate chain during a SSL/TLS handshake, does not prompt the user before searching for and finding a newer certificate, which may allow attackers to perform a man-in-the-middle attack. NOTE: it is not clear whether this poses a vulnerability.  Assigned (20050629)  None (candidate not yet proposed)    View

Page 1717 of 20943, showing 5 records out of 104715 total, starting on record 8581, ending on 8585

Actions